I am investigating the switch from our current mail system (Novell Groupwise)
to Exchange 2003.

My first question relates to the outlook web access component. With our
current Groupwise setup we have a seperate webserver in the DMZ to handle
webmail. I know with Exchange 2003 you need to do a seperate install to a
second box and make this box a front-end server. At this point the server
needs to communicate to Active Directory, so I have two options.

1) Leave the webmail server in my internal network, NATing the outside port
80/443 to the internal.

2) Putting the webmail server in the DMZ and opening up various ports to
allow webmail to access the internal Active Directory.

There are advantages/disadvantages to both setups. Ideally I'd like to setup
a second domain in the DMZ and configure a one-way trust to my internal
domain (I have other servers that could take advantage of this as well). For
customers that have webmail available, what have you done in regards to this
topology?

Re: Adv/disadv of having webmail server in DMZ or internal by Nick

Nick
Wed Jan 18 15:40:07 CST 2006

Personally I prefer OWA inside - DMZ to me is a thing of the past. I always
do OWA on the LAN and depending on budget it is either on the Exchange box
itself or FE/BE OWA is money allows.

"Robin" <Robin@discussions.microsoft.com> wrote in message
news:0D175719-C48B-4E9E-85D1-C2982D884BE6@microsoft.com...
>I am investigating the switch from our current mail system (Novell
>Groupwise)
> to Exchange 2003.
>
> My first question relates to the outlook web access component. With our
> current Groupwise setup we have a seperate webserver in the DMZ to handle
> webmail. I know with Exchange 2003 you need to do a seperate install to a
> second box and make this box a front-end server. At this point the server
> needs to communicate to Active Directory, so I have two options.
>
> 1) Leave the webmail server in my internal network, NATing the outside
> port
> 80/443 to the internal.
>
> 2) Putting the webmail server in the DMZ and opening up various ports to
> allow webmail to access the internal Active Directory.
>
> There are advantages/disadvantages to both setups. Ideally I'd like to
> setup
> a second domain in the DMZ and configure a one-way trust to my internal
> domain (I have other servers that could take advantage of this as well).
> For
> customers that have webmail available, what have you done in regards to
> this
> topology?
>
>