Recommended Posts

One of my customers is having us setup an Exchange 2013 cluster with Windows Server 2012, but they want us to use a DMZ Network on their firewall.

Because the server roles have changed, and Exchange will need Active Directory services, we're wondering if the best case scenario to meet there security expectations is to create a Virtual machine with Exchange 2010 transport roles in the DMZ.

Will this setup/configuration work or is this not recommended?

Will any ports have to be opened for the 2010 transport server to communicate with active directory?

depending on how the dmz is setup, you will need ports 25 (for mail in and out), 50389 and 50636 (these two ports are for secure active directory) and if you want to manage with rdp 3389. You will be fine with putting this in a vm server.

depending on how the dmz is setup, you will need ports 25 (for mail in and out), 50389 and 50636 (these two ports are for secure active directory) and if you want to manage with rdp 3389. You will be fine with putting this in a vm server.

Thanks dude.... now is the Transport Server what we need to make this work with the DMZ? I'm installing Hyper V/Server 2k8 with Exchange 2k10 as we speak.....

What we want is to place the edge transport server in the DMZ with the least amount of open ports to meet the company's network security policies.

Can this server be a standalone server that is not a member of the domain with it's only purpose is to be a transport server?

Would you be wanting an edge transport server role then? Your wanting to simply have something in the DMZ to accept traffic on port 25 and perform simple spam/security checks which isn't AD reliant?

I think you maybe confusing Edge transport (not AD reliant and made for DMZ) with hub transport (AD Reliant, needs to be 'inside')?

Exchange 2010 Edge Transport

Edge Transport is an optional role that can be installed to prevent spam and virus. This role is meant to replace spam filtering devices such as Barracuda Spam firewall and Symantec mail security. This role is installed on a stand-alone server (workgroup) and uses ADAM to sync LDAP data from Active directory. This allows recipient filtering on Edge Transport server.

What we want is to place the edge transport server in the DMZ with the least amount of open ports to meet the company's network security policies.

Can this server be a standalone server that is not a member of the domain with it's only purpose is to be a transport server?

Sorry for my earlier posts, juts seen this of yours where you clearly state you want to put the Edge transport role in the DMZ.

You'll need to configure ADAM (Active Directory Application Mode) so that the edge transport server (workgroup not domain member) can 'talk' to AD and filter recipients correctly.

This topic is now closed to further replies.
  • Posts

    • I called it last year that they wouldn't end support when they said there would. There are too many people still on Windows 10 waiting for something better to upgrade to and 11 ain't it! The recent promises of fixing Windows 11's many problems is nice, but unless they deliver on those promises in a big way then I expect customers will still want to stick with 10.
    • Full ACK. I went too far adressing your post specifically. And as you said, it up to us customers as participant of the market dynamic as it happens to decide whether we spend our money on a product or not. The responsibility is to the company. In case of this price hike one could assume that MS is expecting or even starting to see a new interest in XBox hardware so they want to avoid losses per unit sold. I find it fair enough that they granted a period in which everyone interested could grab a unit for the current price (Amazon.de has a reliable stock of XBox Series X digital, which I bought last December after having sold my day one Series X a year ago). It is not that they cash up their customers starting on Monday. Cheers and let's cling to our perfectly fine hardware as long as we deem it worthy in relation to purchasing something new!
    • Not surprising at all. Apple got three months worth of marketing hype with the Macbook Neo's incredible low launch price. They have sowed the idea that the Neo is the best value laptop and that idea will last for years even though the value is no longer there. They do this every five years or so with a single new product that is amazing value which distracts from the rest of their products being horrendously overpriced.
  • Recent Achievements

    • Week One Done
      xvvxcvv earned a badge
      Week One Done
    • One Month Later
      xvvxcvv earned a badge
      One Month Later
    • Enthusiast
      Xonos went up a rank
      Enthusiast
    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      408
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      129
    4. 4
      neufuse
      69
    5. 5
      Xenon
      68
  • Tell a friend

    Love Neowin? Tell a friend!