Mail server inside the network...Safe?

Mail server inside the network...Safe?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Mail server inside the network...Safe? John Smith 09-06-2007
Posted by John Smith on September 6, 2007, 11:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

We are a single server network with Exchange server running on the same box.
Is it a recless move to place this server inside the network rather than the
DMZ?

Thanks for your input.
John



Posted by Ansgar -59cobalt- Wiechers on September 10, 2007, 11:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> We are a single server network with Exchange server running on the
> same box. Is it a recless move to place this server inside the network
> rather than the DMZ?

Yes.

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich

Posted by Newbie72 on September 11, 2007, 8:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sep 10, 11:45 am, Ansgar -59cobalt- Wiechers
> > We are a single server network with Exchange server running on the
> > same box. Is it a recless move to place this server inside the network
> > rather than the DMZ?
>
> Yes.
>
> cu
> 59cobalt
> --
> "If a software developer ever believes a rootkit is a necessary part of
> their architecture they should go back and re-architect their solution."
> --Mark Russinovich

To add to that.. You need a domain controller in order to run exchange
so you have done one of 2 things either you are running SBS and you
have installed exchange on it or you are running 2003 server which you
have promoted to a domain controller and you installed exchange on it.
Either way installing exchange on domain controller is not a
recommended configuration according to microsoft.

Check out this link it has several other links as to why Microsoft
says it is a no no.

http://blogs.brnets.com/michael/archive/2005/01/24/319.aspx

Never put a domain controller or a exchange server directly on public
name space without using NAT and access lists to control what ports
will be allowed open unless the Exchange server is a Front end
relaying info to a backend cluster. Even then it is recommended to
have a router with some kind of access list to protect it with.


Posted by John Smith on September 11, 2007, 5:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Actually this is a brand new network. There will be only one server for
some time. This server will be the DC as well as have the Exchange Server
2007 running on it. So, that is why I am not sure where I should put in the
network or the DMZ.

Can I put this on the DMZ and install a second NIC, one NIC connected to the
DMZ and the other to the private network?

Thanks,
John

So I am not sure whether I should put this server (the only server)
> On Sep 10, 11:45 am, Ansgar -59cobalt- Wiechers
>> > We are a single server network with Exchange server running on the
>> > same box. Is it a recless move to place this server inside the network
>> > rather than the DMZ?
>>
>> Yes.
>>
>> cu
>> 59cobalt
>> --
>> "If a software developer ever believes a rootkit is a necessary part of
>> their architecture they should go back and re-architect their solution."
>> --Mark Russinovich
>
> To add to that.. You need a domain controller in order to run exchange
> so you have done one of 2 things either you are running SBS and you
> have installed exchange on it or you are running 2003 server which you
> have promoted to a domain controller and you installed exchange on it.
> Either way installing exchange on domain controller is not a
> recommended configuration according to microsoft.
>
> Check out this link it has several other links as to why Microsoft
> says it is a no no.
>
> http://blogs.brnets.com/michael/archive/2005/01/24/319.aspx
>
> Never put a domain controller or a exchange server directly on public
> name space without using NAT and access lists to control what ports
> will be allowed open unless the Exchange server is a Front end
> relaying info to a backend cluster. Even then it is recommended to
> have a router with some kind of access list to protect it with.
>



Posted by Leythos on September 11, 2007, 5:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
jsmith@nospamplease.com says...
>
> Actually this is a brand new network. There will be only one server for
> some time. This server will be the DC as well as have the Exchange Server
> 2007 running on it. So, that is why I am not sure where I should put in the
> network or the DMZ.
>
> Can I put this on the DMZ and install a second NIC, one NIC connected to the
> DMZ and the other to the private network?

If your Exchange server is the only Exchange server, and it's a single
server for the network, why would you even think that putting it in the
DMZ would protect anyone?

Unless you make it a stand-alone DC/Exchange box, with NO CONNECTION to
the LAN servers/AD structure, you're going to have to allow replication
between it and the LAN, which means that if they hack it, they get the
rest of your network.

SBS 2003 runs as a single server DC with Exchange, and it's painless.

If you have a real firewall you can block a lot of countries (unless you
need email from them) and your SPAM/AV filter that is EXCHANGE AWARE can
protect the store - not to mention that most firewalls can remove bad
headers, bad message sizes, bogus headers, and even remove content based
on mime type from messages.

So, the server as a DC, in the LAN, is the only place for it - putting
it in the DMZ would defeat the reason for having a DMZ.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Similar ThreadsPosted
Forwarding more then one mail server and two different domains March 31, 2006, 11:23 am
Forwarding more then one mail server and two different domains March 31, 2006, 11:23 am
Any Firewall Appliance to Front End Web and Mail Server? March 19, 2008, 11:46 pm
Inbound Mail Server Connect and Reject by Firewall December 8, 2007, 3:11 am
SMTP Server Inside LAN to Receive Router Firewall Logs July 13, 2005, 2:16 pm
PIX: Ping VPN host from inside network March 22, 2007, 3:46 pm
How safe us my wireless network May 12, 2007, 3:30 pm
Network topology suggestions for Win2k3 web server network March 1, 2005, 9:58 am
Allow printing traffic from DMZ(Lower Security interface) to inside network on PIX 515E December 8, 2005, 2:53 pm
Setting up linksys RV016 as PPTP server, cannot see network machines October 21, 2007, 3:54 pm

The site map in XML format XML site map

Contact Us | Privacy Policy