Computing.Net > Forums > Windows Server 2003 > exchange 2003 and firewall

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

exchange 2003 and firewall

Reply to Message Icon

Name: Saleh
Date: May 25, 2007 at 05:43:18 Pacific
OS: W3K
CPU/Ram: 3.2,2gb
Comment:

hi there,
i've setup exchange 2003 server on our domain controler (win2003)
all our workstations connect to the exchange server using outlook 2003 without any problems only if we turn windows firewall off on the exchange server but when i turn the firewall on no one can connect.
i tried to do a search on ports that exchange uses but i only found the common onces which i tried to open like port 25smtp,110pop,143imap,389Ldap.
if you could tell me which ports i need to open in order to access the exchange server from the local LAN.

Thanks in advance for any suggestions




Sponsored Link
Ads by Google

Response Number 1
Name: heropsycho2177
Date: May 25, 2007 at 05:47:19 Pacific
Reply:

Normal Outlook uses RPC ports. That involves a port mapper and then a random port.

FYI, if you're that concerned about security, you should never have installed Exchange on a DC.

"Enough, enough bowing down to disillusion!
Hats off & applause to rogues & evolution!
The ripple effect is too good not to mention.
If you’re not affected, you’re not paying attention!"


0

Response Number 2
Name: Saleh
Date: May 25, 2007 at 08:30:46 Pacific
Reply:

Thanks heropsycho2177 for your reply
you showed the way to my answer.
i've done a search in google for Exchange server static port mappings and took me to microsoft site KnowledgeBase 270836
will try and modify the registry.
Thanks again


0

Response Number 3
Name: heropsycho2177
Date: May 25, 2007 at 09:35:15 Pacific
Reply:

In case you're reading this...

I applaud security, I really do. But think about what gains you're actually getting from Windows Firewall on this server. Since it's a DC, you must allow SMB, LDAP, etc.

Since it's Exchange you have to allow SMTP, RPC, HTTP, etc.

If your machine is going to be attacked from an unsolicited connection, it's gonna be on one of those ports anyway.

Windows Firewall does no egress filtering.

If this were a DMZ host or something, I understand using it, but on an internal LAN when you HAVE to open the ports most exploited, and you gain no egress filtering, what exactly do you think you're accomplishing with Windows Firewall on?

Your vulnerabilities are you're exposing a server housing all domain accounts, including admins, to direct traffic from the internet, to any application layer vulnerabilities in Exchange, etc.

That's what you should be concerned about, not unsolicited connections on random ports that are closed anyway.

"Enough, enough bowing down to disillusion!
Hats off & applause to rogues & evolution!
The ripple effect is too good not to mention.
If you’re not affected, you’re not paying attention!"


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Disconnected Network Driv... sp2 internet problem



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: exchange 2003 and firewall

exchange 2003 and windows 2003 www.computing.net/answers/windows-2003/exchange-2003-and-windows-2003/936.html

Exchange 2003 And Outlook 2003 www.computing.net/answers/windows-2003/exchange-2003-and-outlook-2003/6660.html

E-mail problem - Exchange 2003 HELP www.computing.net/answers/windows-2003/email-problem-exchange-2003-help/3144.html