Networking Forums

Networking Forums > Computer Networking > Windows Networking > DMZ and AD for Exchange 2003

Reply
Thread Tools Display Modes

DMZ and AD for Exchange 2003

 
 
C Emmons
Guest
Posts: n/a

 
      08-14-2004, 12:51 AM
I am running Exchange 2003 SP1 on Windows Server 2003. I
am using the Front-End/Back-End Topology. The Exchange
Front-End passes request for mail to the Back-End. I
paid a consultant to come in and setup a DMZ in which the
Front-End now resides. As far as I can see, the
connectivity seems okay between the front and the back.
However, the front-end server will not work. I get the
following error:

All DS Servers in domain are not responding.

Outside the DMZ (IP changed back to my internal network) -
everyone works fine between front and back.

I have two Domain Controllers running Windows 2003 Server
Enterprise (Clusters). The Exchange Server is of course
in the domain, but is not a domain controller.

Can anyone please help - I am trying to meet a deadline
and the consultant has gone. Help much appeciated.
C Emmons
 
Reply With Quote
 
 
 
 
Miha Pihler
Guest
Posts: n/a

 
      08-14-2004, 08:29 AM
Hi,

if you have Front-End server in DMZ and DC in LAN, you have to open a bunch
of ports that will allow front end server to connect to back end servers.
Besides being able to connect to back end server it has to be able to
connect to DCs which in your case is not able. Also DNS settings (under
TCP/IP properties) on your Front End must point to DNS server that knows
something about your domain -- you will probably have to configure it to
connect to DC for all DNS queries. Again you will have to check on your
firewall is this allowed.
Here are some additional information what you might need to open from DMZ to
LAN (but you might as well consult your firewall logs and see what is being
dropped).

http://www.microsoft.com/serviceprov...sec_P63623.asp

I know this article talks about replication of DCs over firewall, but most
of the ports are the same. You will only have to add SMTP TCP port (TCP port
25).

Mike

"C Emmons" <(E-Mail Removed)> wrote in message
news:609501c48198$e5f11290$(E-Mail Removed)...
> I am running Exchange 2003 SP1 on Windows Server 2003. I
> am using the Front-End/Back-End Topology. The Exchange
> Front-End passes request for mail to the Back-End. I
> paid a consultant to come in and setup a DMZ in which the
> Front-End now resides. As far as I can see, the
> connectivity seems okay between the front and the back.
> However, the front-end server will not work. I get the
> following error:
>
> All DS Servers in domain are not responding.
>
> Outside the DMZ (IP changed back to my internal network) -
> everyone works fine between front and back.
>
> I have two Domain Controllers running Windows 2003 Server
> Enterprise (Clusters). The Exchange Server is of course
> in the domain, but is not a domain controller.
>
> Can anyone please help - I am trying to meet a deadline
> and the consultant has gone. Help much appeciated.
> C Emmons



 
Reply With Quote
 
Jetro
Guest
Posts: n/a

 
      08-15-2004, 03:07 PM
Please read
http://www.microsoft.com/technet/pro...y/febetop.mspx,
Microsoft Exchange Server 2003 and Exchange 2000 Server Front-End and
Back-End Topology
about perimeter networks and firewalls.

Do not "open ports" in a firewall but create rules.

 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      08-16-2004, 04:05 PM
I think this is a pretty bad situation. The amount of exposure you have to
create between the DMZ and the LAN for this to work pretty much nullifies
the DMZ. You could rig up VPN that is designed to only run between the Front
Exch and some kind of VPN Server that sits on the "line" between the LAN and
DMZ,...the Exch would then see the LAN DC's and other Exch via the VPN.
However this means that if the Front Exch is compromised the Exch box can
provide an avenue into the LAN via the VPN just as opening up the DMZ doing
it the "other" way would have done.

I am not convinced that running two Exch's (front & back) is really very
secure since the fact that the Front Exch has to communicate unhindered with
the Back Exch, and that seems to nullify any security it was supposed to
have provided.

I think a single Exchange properly configured, maintained, and published
from behind a Firewall will do just fine.

But that is just my opinion.

--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


"C Emmons" <(E-Mail Removed)> wrote in message
news:609501c48198$e5f11290$(E-Mail Removed)...
> I am running Exchange 2003 SP1 on Windows Server 2003. I
> am using the Front-End/Back-End Topology. The Exchange
> Front-End passes request for mail to the Back-End. I
> paid a consultant to come in and setup a DMZ in which the
> Front-End now resides. As far as I can see, the
> connectivity seems okay between the front and the back.
> However, the front-end server will not work. I get the
> following error:
>
> All DS Servers in domain are not responding.
>
> Outside the DMZ (IP changed back to my internal network) -
> everyone works fine between front and back.
>
> I have two Domain Controllers running Windows 2003 Server
> Enterprise (Clusters). The Exchange Server is of course
> in the domain, but is not a domain controller.
>
> Can anyone please help - I am trying to meet a deadline
> and the consultant has gone. Help much appeciated.
> C Emmons



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
outlook 2003 freezes and looses connection with exchange server 2003 RC Windows Networking 2 04-26-2007 03:48 PM
External Associated Account in Windows Server 2003 and Exchange 2003 shi171@gmail.com Windows Networking 0 03-12-2006 09:30 PM
Disable NetBIOS and NTLM on Windows 2003 Domain Controllers and Exchange 2003? Research Services Windows Networking 8 10-06-2004 12:15 AM
SBS and exchange 2003 Eric Vartanian Windows Networking 1 09-24-2004 01:16 AM
EXCHANGE 2003 on a Windows Storage Server 2003 Amjad Windows Networking 4 07-31-2004 01:53 AM



1 2 3 4 5 6 7 8 9 10 11