OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NFR Wizards Archives: RE: How do folks firewall MS Exchange? an

RE: How do folks firewall MS Exchange? and Web-based access to Ou tlook securely


Cracknell, Phil (phil.cracknellnomura.co.uk)
Thu, 25 Nov 1999 08:37:37 -0000


Dan,

We've been looking at WTS to offer remote users access to certain desktop
apps including mail through the firewall.
Problem we found is that Cytrix's Java client doesn't use secure ICA and is
'all over the shop' leaving the firewall severely weakened. We've toyed with
SSL but using WTS some info still goes clear text outside this session.
Cytrix will have a secure version of this q2 2000.

I'd be interested to hear or solutions/product to allow my users to securely
access their desktop apps via the Internet. Client-side code is out because
the system might be in an airport lounge for example.

Sun's Iplanet looks like it might do the job but on paper seems very slow.
Any experience?

Rgds

Phil

-----Original Message-----
From: Dan Schlitt [mailto:schlittworld.std.com]
Sent: 24 November 1999 13:35
To: firewall-wizardsnfr.net
Subject: Re: How do folks firewall MS Exchange?
Importance: Low

Back in October I asked this question. Thanks to everyone who provided
helpful information. We did get a solution using ssh. This messages is
delayed because we wanted to test the solution.

Although the port forawding on ssh works, MS evidently puts the hostname
information somewhere and that makes things fail.

We are using Notes which does not have this problem.

/dan

-- 

Dan Schlitt schlittworld.std.com

On Thu, 7 Oct 1999, Dan Schlitt wrote:

How do folks work access to an MS Exchange server through a firewall?

We are under pressure to install MS Exchange in our mixed unix/NT environment and allow access from outside our local network.

I checked the archives and didn't find anything that helped me.

Currently we limit outside access from the Internet to ssh to a unix host. Port forwarding makes it possible to do all of the things that have been required in the past. But now the folks on the sales side of the company want to have MS Exchange installed so they can use its calendaring and other functions.

We have attempted to use the port forwarding to make exchange work and we have also tried Lotus Notes. No luck. Maybe we have missed something. This would be our preferred approach.

So we are now looking for a firewall solution to this problem. Have any of you our there encountered this problem. How did you solve it?

Thanks.

/dan

-- 

Dan Schlitt schlittworld.std.com



This archive was generated by hypermail 2.0b3 on Sun Nov 28 1999 - 18:16:04 CST