Firewall Wizards mailing list archives
Re: Exchange 2003 OWA security questions
From: Kevin <kkadow () gmail com>
Date: Wed, 19 Jan 2005 00:34:10 -0600
On Tue, 18 Jan 2005 20:46:38 -0500, MHawkins () tullib com <MHawkins () tullib com> wrote:
We use CheckPoint/Nokia with multiple DMZ's including a web server farm DMZ. Our Microsoft admin wants to multihome an ISA server on our web dmz with the other NIC connected to our internal network to allow the ISA to talk to the internal MS OWA front end server which then talks to the exchange server (sheesh!). All this to allow users on the internet to access exchange via a web browser.
Our MS salesdroids have tried to sell use the same bill of goods as above, multiple pitches over the past 18 months, without success. Why not put the ISA server out on the web DMZ, and pass cleartext HTTP traffic through the Checkpoint firewall from the ISA to the "internal MS OWA front end server"? This gives the Checkpoint and other security devices a chance to inspect the HTTP stream. Alternately, replace the ISA with something like the Whale "e-Gap Webmail System"? I'm not saying that the "e-Gap" doesn't smell a whole lot like snake oil, but they do have a strong (and relatively inexpensive) solution for securing OWA. Unlike ISA which (according to the above salesdroids) protects OWA by detecting known attacks, Whale has a model of what constitutes valid OWA requests, and denies anything not matching good behavior -- the classic "that which is not explicitly permitted is denied" model from Firewalls 101.
I asked the MS admin to single home his ISA or forget about ISA altogether and just run a front end server in the web dmz. The idea of breaking our Checkpoint architecture with an ISA that multihomes between the internal network and our web dmz is just too much to ask a decent security admin don't you think. Now I need ammunition to press the point home.
Absolutely. You have a functional Nokia firewall, it would be a mistake to parallel your existing firewall with ISA, charitably described as a firewall-like Microsoft Windows server.
ii) Scrap the ISA server, I think the front end server should be on the web dmz. Does everyone agree with this? Yes, I know I have to open up all those nasty MS ports but atleast I can restrict it to talking to the DC's and a few other boxes - those would be hardened machines anyways.
This approach worked under older versions of Exchange/OWA, but the port problem gets much much worse under Exchange 2003, OWA 2003 and AD. You end up opening huge ranges of ports to/from the front end server for all internal Exchange stores and DC's. One RPC hole, and the whole enterprise is owned.
iii) I think the MS admin should just run a front end server internally and also another front end server on the web dmz. That way, you can harden the web dmz machine properly but don't have to worry about the one that's only for internal use (ok not too much worry). Make sense?
Makes sense. Expensive and potentially difficult to sell to management, but it does make sense. Kevin Kadow _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: Application-level Attacks, (continued)
- Re: Application-level Attacks Danny (Jan 28)
- Re: Application-level Attacks Crispin Cowan (Jan 28)
- Re: Application-level Attacks Paul D. Robertson (Jan 28)
- Re: Application-level Attacks Marcus J. Ranum (Jan 29)
- Re: Application-level Attacks Paul D. Robertson (Jan 29)
- Re: Application-level Attacks Dean A Weber (Jan 28)
- Re: Application-level Attacks Dave Piscitello (Jan 28)
- Re: Application-level Attacks R. DuFresne (Jan 28)
- Message not available
- Re: Application-level Attacks Marcus J. Ranum (Jan 29)
- RE: Application-level Attacks Ben Nagy (Jan 28)
