Firewall Wizards mailing list archives

Re: Exchange 2003 OWA security questions


From: Kevin <kkadow () gmail com>
Date: Wed, 19 Jan 2005 00:34:10 -0600

On Tue, 18 Jan 2005 20:46:38 -0500, MHawkins () tullib com
<MHawkins () tullib com> wrote:
We use CheckPoint/Nokia with multiple DMZ's including a web server farm DMZ.

Our Microsoft admin wants to multihome an ISA server on our web dmz with the
other NIC connected to our internal network to allow the ISA to talk to the
internal MS OWA front end server which then talks to the exchange server
(sheesh!). All this to allow users on the internet to access exchange via a
web browser.

Our MS salesdroids have tried to sell use the same bill of goods as
above, multiple pitches over the past 18 months, without success.

Why not put the ISA server out on the web DMZ, and pass cleartext HTTP
traffic through the Checkpoint firewall from the ISA to the "internal
MS OWA front end server"?  This gives the Checkpoint and other
security devices a chance to inspect the HTTP stream.

Alternately, replace the ISA with something like the Whale "e-Gap
Webmail System"?  I'm not saying that the "e-Gap" doesn't smell a
whole lot like snake oil, but they do have a strong (and relatively
inexpensive) solution for securing OWA.   Unlike ISA which (according
to the above salesdroids) protects OWA by detecting known attacks,
Whale has a model of what constitutes valid OWA requests, and denies
anything not matching good behavior -- the classic "that which is not
explicitly permitted is denied" model from Firewalls 101.


I asked the MS admin to single home his ISA or forget about ISA altogether
and just run a front end server in the web dmz. The idea of breaking our
Checkpoint architecture with an ISA that multihomes between the internal
network and our web dmz is just too much to ask a decent security admin
don't you think. Now I need ammunition to press the point home.

Absolutely.  You have a functional Nokia firewall, it would be a
mistake to parallel your existing firewall with ISA, charitably
described as a firewall-like Microsoft Windows server.

ii) Scrap the ISA server, I think the front end server should be on the web
dmz. Does everyone agree with this? Yes, I know I have to open up all those
nasty MS ports but atleast I can restrict it to talking to the DC's and a
few other boxes - those would be hardened machines anyways.

This approach worked under older versions of Exchange/OWA, but the
port problem gets much much worse under Exchange 2003, OWA 2003 and
AD.

You end up opening huge ranges of ports to/from the front end server
for all internal Exchange stores and DC's.  One RPC hole, and the
whole enterprise is owned.


iii) I think the MS admin should just run a front end server internally and
also another front end server on the web dmz. That way, you can harden the
web dmz machine properly but don't have to worry about the one that's only
for internal use (ok not too much worry). Make sense?

Makes sense.  Expensive and potentially difficult to sell to
management, but it does make sense.


Kevin Kadow
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: