I think your customer's fears aren't completely unfounded. Exchange 2000
handles a DMZ-resident OWA server better than Exchange 5.5, but the
potential for a security breach by passing port 443 (SSL) through to an
internal server is pretty small. It might be even smaller if you implement
a VPN.
Ed Crowley MCSE+Internet MVP
Tech Consultant
Compaq Computer Corporation
All your base are belong to us.
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Eric Cooper
Sent: Friday, August 24, 2001 7:16 PM
To: Exchange Discussions
Subject: IIS Front End to OWA 2000?
I'm currently in the early planning phase of an enterprise messaging rollout
for a smallish company. I'm well-experienced with Exchange 5.5 and OWA and
I've done my share of reading and research on Exchange 2000. The problem is
that I've got a client with a pre-existing "fearofExchangeintheDMZ" disease.
Since I obviously need to host whatever WWW service for OWA in the DMZ, I
need some advice on the front end. Can a vanilla IIS 5.0 installation
support the web services for OWA inside the corporate LAN? I've found
plenty of info on doing OWA Front End/Back End configurations, but none on
IIS-->OWA ones. Is this possible, or does IIS have problems authenticating?
or are there ISAPI problems, etc?
If this can't be done, I have no problems telling the client that I'm going
to put Exchange in his DMZ and do a standard F/E B/E config but I'm going to
have to convince him and his cronies that their AD and message store is
still safe.
Thanks.
Eric
_________________________________________________________________
List posting FAQ: http://www.swinc.com/resource/exch_faq.htm
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:[EMAIL PROTECTED]
Exchange List admin: [EMAIL PROTECTED]
_________________________________________________________________
List posting FAQ: http://www.swinc.com/resource/exch_faq.htm
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:[EMAIL PROTECTED]
Exchange List admin: [EMAIL PROTECTED]