Solved

Exchange 2003 Network Design Question

Posted on 2006-07-19
10
285 Views
Last Modified: 2010-03-06
We are currently planning a Groupwise to Exchange conversion (I know---why go to Exchange, but we were told we had to).  My task is to come up
with the most secure, yet functional implementation of the server layout / design.  We have a heavy use of OWA and about 1000+ accounts.  What
would be the best way to setup the design?  We are to use an appliance for the SPAM / AntiVirus as well.  I am stuck between Barracuda and Symantec's 8200 series.  I currently have though of 4 different layouts...

We have a Firewall - DMZ - Internal Network

1.  FW |  Appliance + Front End Servers | FW | Back End Servers and AD
           I put this in just so I could shoot it down.  I am not planning on this but maybe the experts think it is the best.
2.  FW |  Appliance + Apache on sun/linux | FW | Front End Servers, Back End Servers, and AD
           I am leaning towards this approach
3.  FW |  Appliance + ISA Server | FW | FES, BES and AD
           MS recommends the ISA server obviously but it seems overkill in my situation
4.  FW |  CipherTrust Appliance + CipherTrust proxy | FW | FES, BES, AD
           Cipher Trust supposedly has 2 appliances that can do the proxying and AntiVirus / AntiSpam (We are still researching)

Does anyone have any suggestions on what layout to use and what appliance to go with?  There really is not a budget.  I was told to make it work
in the most effective yet secure way :)
0
Comment
Question by:Addpcg
  • 3
  • 3
  • 2
10 Comments
 
LVL 37

Expert Comment

by:Jamie McKillop
Comment Utility
You have to ask why go to Exchange from Groupwise? :)

Solution 1 is the best solution (IMHO). You want your FE servers in your DMZ, that is the whole point of the FE servers. You expose them instead of your mailbox server and you don't need to punch a hole through your firewall from the Internet to your internal network. Use your appliance to handle incoming and outgoing SMTP traffic (BTW - I recommend you look at Tumbleweed) and use the FE server for OWA and RPC over HTTP traffic.

JJ
0
 

Author Comment

by:Addpcg
Comment Utility
By having the Front End Servers in the DMZ, do you not have to open a TON of ports including all the RPC ports, not just 443 and 25?  I am new to the Exchange world.  I supported Lotus Notes and Groupwise on the perimeter end by using postfix among other Internet Email solutions so this is
kind of new to me.
Thanks!
0
 
LVL 37

Expert Comment

by:Jamie McKillop
Comment Utility
From the FE server to your BE and AD server, yes there are a number of ports that need to be open. From the Internet to the FE you only need to open 443 if you are just going to use them for OWA and RPC over HTTP. You will be using your appliance for SMTP traffic so the FE server won't need to send/receive SMTP to the Internet.

JJ
0
 

Author Comment

by:Addpcg
Comment Utility
We are actually going to use the FE servers for OWA, OMA, and Public Folders but yes it should only be 443.  From a security standpoint is that more secure than having a linux / sun box proxying to the FE severs on the inside?  I am just a little leary of putting Exchange Servers in the DMZ (even though the only ports open to the outside is minimal).  That was my thought anyway so I am asking the experts.
0
Want to promote your upcoming event?

Is your company attending an event or exhibiting at a trade show soon? Are you speaking at a conference? Spread the word by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

 
LVL 37

Expert Comment

by:Jamie McKillop
Comment Utility
To be honest, I'm not a security expert so I can't really give an expert opinion on which method is more secure. Like you said though, the exposure would be minimal and any potential attack over port 443 would probably be sent by the Linux proxy to the FE server anyway.

JJ
0
 
LVL 104

Accepted Solution

by:
Sembee earned 250 total points
Comment Utility
For me, I would go with option three. I have deployed almost the same solution for a number of finance houses and it has got past their internal security people.

When it comes to introducing a proxy box, then that is where your skillset comes in. Are you comfortable with securing a proxy on Linux/Solaris?

Simon.
0
 

Author Comment

by:Addpcg
Comment Utility
We have Apache "experts" in the company that has experience doing this so it should not be an issue.  We would just proxy all (i use that loosely) 443 requests inside the FW to the FE servers.  That way there isn't a plethera of "risks" with open ports and vulnerable OS's exploits in the DMZ.
0
 
LVL 104

Expert Comment

by:Sembee
Comment Utility
The primary concern must be what skills you have - without the skills then your security is compromised, because you cannot recognise what the problem is.
Therefore if you have the skills in house - and will retain the skills (ie if someone was to leave they would be replaced) then go with what you can do.

Simon.
0

Featured Post

The curse of the end user strikes again      

You’ve updated all your end user’s email signatures. Hooray! But guess what? They’re playing around with the HTML, adding stupid taglines and ruining the imagery. Find out how you can save your signatures from end users today.

Join & Write a Comment

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now