• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 297
  • Last Modified:

Need to Secure my internet facing CAS server


We have an exchange 2010 architecture that contains a site A and a site B. Site A is internet facing behind a firewall and we need to secure the CAS server from an IIS perspective because the default IIs page is showing when you try and access the site without the /owa at the end.
Could anyone please assist with this process
1 Solution
Not sure this is really a question of "securing" the IIS server.  Either you're allowing traffic on TCP 80/443, or not.  If you're running OWA on this box, you are.  If you're not running any other custom content on the IIS server, then it will be as secure as OWA can be - so long as you keep your updates current.

From a security perspective, don't run additional sites (especially apps) on the OWA server.  Don't install custom web components, either - just run what Exchange installed to support OWA.

As for the default IIS page, you might write a page that redirects incoming traffic to /owa - preferably using https.  You need only put actual content on the default web root to make the default IIS page go away.

Example default.aspx:
<%@ Page Language="C#" %> 
<script runat="server"> 
  protected override void OnLoad(EventArgs e) 

Open in new window

Or default.html:
<meta HTTP-EQUIV="REFRESH" content="0; url=https://[YourServerName.somewhere.com/owa"> 

Open in new window

Hope that helps!
ablsysadminAuthor Commented:
thanks, will give it a try asap and report back
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now