Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Exchange Server / Design / October 2006

Tip: Looking for answers? Try searching our database.

Outbound Internet Mail

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
andyjones99@hotmail.co.uk - 18 Oct 2006 14:21 GMT
Hello All

We have a requirement to route outbound internet email from Exchange
2003.

As a solution I have decided to build 2 Exchange BH servers and install
an SMTP connector wich utilises both these virtual servers.

These 2 BH servers will be on our internal network and will send mail
out directly to the internet. The firewall policy will only allow port
25 from these servers outbound to the internet.

These 2 BH servers will also run Antigen 9.0 for AV protection and
possibly we will inplement either IMF or the Antigen spam module for a
second level of spam protection for the Internet mail we receive via
our parent company.

Does this sound like a good solution?

I have gone through loads of other possible designs but have settled on
this. One of the other designs included having an SMTP gateway on our
DMZ which the Exchange clusters virtual server relayed too. I decided
that as we do not need to provide for incoming internet email (as that
is routed to us internally by the parent company) it is pointless
installing a box on the DMZ, this would just make it harder to manage
as opposed to providing any security benefit as connections are
outbound only

Incoming mail that we receive from our parent company will also be
routed to the two BH servers, we plan to utilise DNS round robin here
as opposed to deploying NLB.

We also have a single FE server on our internal network that supports
EAS and OWA access to Exchange and this is front ended by ISA which is
in the DMZ.

Any comments on this design?

Much appreciated

AndyJ
Bharat Suneja [MVP] - 18 Oct 2006 15:20 GMT
Not commenting on the scale/sizing (which would determine if you can/cannot
use an existing Exchange server as a bridgehead), it looks good.
Signature

Bharat Suneja
MVP - Exchange
www.zenprise.com
NEW blog location:
www.exchangepedia.com/blog
----------------------------------------------

> Hello All
>
[quoted text clipped - 37 lines]
>
> AndyJ
andyjones99@hotmail.co.uk - 19 Oct 2006 14:20 GMT
Thanks for your feedback Bharat

AJ

> Not commenting on the scale/sizing (which would determine if you can/cannot
> use an existing Exchange server as a bridgehead), it looks good.
[quoted text clipped - 47 lines]
> >
> > AndyJ
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2009 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.