owa virtual directory /exchange, any security conern on it?
Thanks all for your all. I'm using exchange 2003 with one owa front end and one back end mailbox server. I found that the "exchange" virtual directory is listed in IIS both on OWA front end and back end server. When using owa to access mail, I will type https://owa.mydomain.com/exchange. Does it mean the exchange directory is visible to public, does it store mailbox information, any security concern on it? if yes, how can I enhance its security? Thanks again Patrick
January 23rd, 2011 9:25pm

Hi Patrick, The only exchange directory that is available to the public, should should be the front end as that ius the job of the edge server. Check you firewall or NAT to ensure it is going to the right place; https://owa.mydomain.com/exchange = IP of front end server The back end can be used for internal web access :) Once you have checked your firewall and patch level you should be well secured. Lew
Free Windows Admin Tool Kit Click here and download it now
January 24th, 2011 4:43am

No. The exchange directory is visible and accessible only to those authenticated user. As you mentioned, you need to type https://owa.mydomain.com/exchange. It means the message between client and FE is encrypted. For enhance the security of BE , you can set DMZ zone. Then set FE inside DMZ, and BE behind DMZ. For more information about FE/BE topology , you can access http://technet.microsoft.com/en-au/library/aa996980(EXCHG.65).aspx
January 24th, 2011 8:18pm

No. The exchange directory is visible and accessible only to those authenticated user. As you mentioned, you need to type https://owa.mydomain.com/exchange. It means the message between client and FE is encrypted. For enhance the security of BE , you can set DMZ zone. Then set FE inside DMZ, and BE behind DMZ. For more information about FE/BE topology , you can access http://technet.microsoft.com/en-au/library/aa996980(EXCHG.65).aspx
Free Windows Admin Tool Kit Click here and download it now
January 25th, 2011 4:11am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics