02-20-2003 06:04 PM - edited 02-20-2020 10:34 PM
I am attempting to configure a PIX 520 to support connections from a low security zone to high security zone inbound to a exchange server from outlook.
I am using the NAT 0 options and have the no problem pinging, hitting the web interface on the same box, or using an IMAP client. I understand that exchange is pretty unique in its use of prots and i have configure dthe
establishes tcp 135 permitto tcp 1024-65535 option but i am drawing a blank. Connectivity still fails. Any suggestions whould be great. Thanks a bunch
02-20-2003 08:33 PM
We have an Exchange server and our clients connect through the PIX using Outlook.
What we did -
First, follow this link for instructions on assigning static ports to Exchange for use with client connections
http://support.microsoft.com/default.aspx?scid=kb;en-us;155831
Then, obviously, setup a static mapping from the high security interface to the low security interface for the Exchange server.
Setup ACLs for port 135, and the two ports you assign via the registry per the above link
Finally, and this is very important, make sure your clients have a means for resolving the Exchange servers host name to an ip address. With Outlook, even if you first enter the IP address into the configuration it automatically converts this to the Hostname upon first connection. You can either use lmhosts files, hosts files, or make sure your mail server has a DNS entry in your clients dns server and the client is properly configured for appending the domain suffix to DNS queries for your domain.
Hope this helps.
~rls
02-21-2003 06:24 AM
Is there a reason you aren't doing this through a vpn? '
http://www.securityfocus.com/archive/1/296114
MS's RPC service stuff on port 135 has had a miserable security history.
02-21-2003 08:04 AM
VPN's nice, but when our consultants are behind a client's firewall it's not always a viable option. And unfortunately Exchange's webaccess leaves a lot to be desired.
There are some other options, like using a relay server. But our current setup has been working great for the past two years without a hitch.
~rls
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide