Home > Ask the Microsoft Exchange Experts > Richard Luckett: Spam and Security Questions & Answers > Outlook Web Access through a firewall
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Outlook Web Access through a firewall

Richard Luckett EXPERT RESPONSE FROM: Richard Luckett

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 November 2004
I am running Exchange 2000 Standard Edition in my organization. We currently use VPN to access e-mail from remote locations. I would like to set up access to Outlook Web Access (OWA) straight through our firewall. Someone told me that I need to set up a front-end server configuration in order to use SSL and configure security correctly. Do I really need a front-end server for SSL, and what are my other options for setting up secure, encrypted OWA?

>
EXPERT RESPONSE
You got some good advice but it is not 100% accurate. You can implement SSL for OWA on your current Exchange 2000. The question becomes -- do you really want to?

In order to set up SSL on any Exchange 2000 or 2003 server, you simply obtain a Web server certificate from a certificate authority (CA). You then configure the Exchange virtual directory in your Default Web site on the Exchange 2000 server to only allow secure HTTP (https://) connections. This will encrypt communications from the Web-based clients to the Exchange server end-to-end using Public Key Cryptography.

An example of a public CA is the well known and very popular VeriSign, which will lease you a certificate that must be renewed periodically. It is also possible to establish your own CA on a Windows 2000 server and manage your own certificates. The process of configuring SSL for OWA is fully detailed in Microsoft KB article 320291, Turning On SSL for Exchange 2000 Server Outlook Web Access.

The next step, as you alluded to, would be to create rules on your firewall(s) to allow communication on ports 80 (HTTP) and 443 (HTTPS) from every external address to your Exchange 2000 server and vice versa. Since your Exchange 2000 server is most likely using a private IP address, you can use Network Address Translation (NAT) on your firewall to translate a public IP address (of your firewall) to the private IP address of your Exchange 2000 server.

So why create a front-end server? A common reason is to add one more layer of security to the mix. Front-end servers do not store data. Therefore they can be locked down and fortified to a greater degree than your current back-end server. Front-end servers can also be strategically placed on the network in a de-militarized zone (DMZ). This area sits between your private network and the Internet, giving you even more control over what communication you will allow in and out of your environment. One or more of these reasons could easily justify you adding a front-end server to your Exchange organization.

If you do decide to go with a front-end server in a DMZ, be prepared to have to open additional ports on your internal firewall to allow the front-end server to function as a member of your Active Directory domain, as described in Microsoft KB article 280132, Exchange 2000 Windows 2000 Connectivity Through Firewalls.

As an alternative to a front-end server, you can consider two other options. You could add a Microsoft ISA (Internet Security and Acceleration) server and use the ISA server to "publish" OWA. This is also known as proxy. The Microsoft ISA server can function as an external firewall, internal firewall and proxy server all-in-one. Microsoft ISA is also Exchange friendly, making it fairly easy to use in a Microsoft-centric environment. See KB article 290113, How to publish Outlook Web Access behind Internet Security and Acceleration Server. And finally, if an upgrade to Exchange 2003 is on your horizon, then it might be worth your time to research RPC over HTTP. Exchange Server 2003 running on Windows Server 2003 can be configured as an RPC proxy server. Outlook 2003 can be configured to send its RPC communications to the server encapsulated in a HTTP header. This can be further secured by enabling SSL communications on the RPC proxy server. This would give you thick client functionality and secure connections without a VPN connection. If you would like more information on RPC over HTTP reach KB article 833401, How to configure RPC over HTTP on a single server in Exchange Server 2003.


Do you have comments on this Ask the Expert Q&A? Let us know.
More information from SearchExchange.com:

  • Tip Library: Outlook Web Access
  • Learning Center: Outlook Web Access
  • Tip Library: Firewalls


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Richard Luckett: Spam and Security
    Selectively set email permissions for Exchange groups
    What event log tracks user access to Exchange Server?
    Public folder permissions fail in Exchange mixed mode
    Locate 'missing' SPF record on an external DNS domain
    Enhance OWA logon security using Microsoft ISA Server
    Native Exchange Server 2003 antispam solutions
    Configure IMF's Gateway SCL to improve spam filtering
    POP3 server filters all email into Junk folder as spam
    Setting up an SSL certificate for OWA without a public IP address
    Creating one password for both local and Microsoft Outlook user accounts

    Outlook Web Access
    Revised Outlook out-of-office (OOF) messages don't update in OWA
    Use the OWA Admin tool to 'segment' Outlook Web Access 2003 features
    Repairing damaged OWA virtual directories in Exchange Server 2003
    Customizing an Outlook Web Access 2003 email signature
    Outlook Web Access limitations using Exchange Server public folders
    OWA won't load after applying Exchange 2007 SP1 security patch
    Minimize remote and mobile Outlook Web Access (OWA) security risks
    How to improve Outlook Web Access (OWA) security
    Alleviate Outlook Web Access (OWA) email attachment security issues
    Customizing Outlook Web Access (OWA) in Exchange Server 2007

    Microsoft Exchange 2000 Server
    Error 1053: Exchange System Attendant service could not start
    Solve server problems with the Exchange Troubleshooting Assistant tool
    Move mailboxes to Exchange 2007 after Windows upgrade
    Third-party tools that modify NDRs for oversized email
    IP address changes for an Exchange 2000 recovery server
    Exchange Server 2003 tips and tricks -- 7 tips in 7 minutes
    How to enable Exchange Server public folder logging
    Deciphering an 0xc103798a Exchange Server setup error code
    Exchange Server error message: 'A non-delivery report with a status code of 5.4.0 was generated for recipient'
    New Exchange Server installation not receiving SMTP or POP3 email
    Microsoft Exchange 2000 Server Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    E2K  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts