Advice configuring Firewall/router for Direct MAPI connection

Posted on 2014-07-15
Last Modified: 2014-08-19
I am moving a company over to a hosted Exchange. The hosting company is asking us to set up a direct MAPI connection to our server. Their instructions suggest :

"Your company Network Administrator should adjust firewall settings to allow connections from Intermedia IP ranges for ALL ports. Also, please make sure the traffic coming in from those ranges is properly NAT-ed to the back-end server"

Th router is an older Draytek device - Vigor 2600. IT doesnt seem to have the option to specify specific ip ranges. How can I therefore NAT their ip range to our Exchange server.

Do I just open the whole range of ports up to the ip address of the server?

Do I put the server in a DMZ? Unlikely I would imagine.

The port redirection table allows me to specify individual ports, but allowing ALL ports would take forever.

Any suggestions?
Question by:roy_batty
    LVL 18

    Expert Comment

    Not exactly familiar with your type of firewall but the following are a standard way of specifying a port range in an access list.

    All you need is appending  the appropriate wild card mask for the range in mind eg
    permit .............. .................... will cover the range to
    permit .............. .................... will cover the range to
    permit .............. .................... will cover the range to

    • A wildcard mask bit 0 means check the corresponding bit value; they must match.
    • A wildcard mask bit 1 means ignore that corresponding bit value; they need not match.

    For port range
    Permitting the whole IP without specifying ports automatically allows all ports for the IP specified

    Hope this helps
    LVL 35

    Expert Comment

    The port redirection page should have a dropdown menu for Single and Range. You want this Range of course.
    The problem is worse though, after you input that, EVERYONE has FULL access to your Exchange server on ALL levels.
    You now have to start closing your firewall for everything and slowly build up exceptions (Intermedia IP range to your server). If InterMedia said only port 5000 through 5500, then it would be much easier, only adding this exception was enough.
    LVL 1

    Accepted Solution

    My Draytek router didnt seem to have the option suggested by Kimputer. In the end I had to put the whole server into the DMZ for a short period whilst the the hosted exchange company exported the required data. Not ideal but it did the job.
    LVL 1

    Author Closing Comment

    The suggestions made did not resolve the issue

    Featured Post

    Want to promote your upcoming event?

    Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

    Join & Write a Comment

    Suggested Solutions

    Title # Comments Views Activity
    Multiple domains for Exchange in Office 365 4 33
    exchange , office 365 4 14
    Exchange 2007 2 11
    exchange 4 4
    Learn more about how the humble email signature can be used as more than just an electronic business card. When used correctly, a signature can easily be tailored for different purposes by different departments within an organization.
    Use these top 10 tips to master the art of email signature design. Create an email signature design that will easily wow recipients, promote your brand and highlight your professionalism.
    In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
    The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    13 Experts available now in Live!

    Get 1:1 Help Now