My situation is a bit unusual due to Balkanized network, email and IT
security responsibilities.

Basically, I will need to setup something in the DMZ to handle Outlook Web
Access and Mobile Access from external points. All email delivery and
sending is handled internally so I don't need that to cross the DMZ. I
pickup and send through enterprise and they take care of AV and spam.
However, they don't (and can not for other reasons) provide mobile access
and OWA which is critical to our needs.

I've got about 80 mailboxes currently running Exchange 2003 with direct
internet connection but will be migrating to 2007 and setting it up on the
internal network. OWA and mobile are currently working well.

Looking at the roles, it appears I'd need to configure an edge transport in
the DMZ but it's not clear to me how this also handles OWA and mobile
access. Most of what I read refers to the SMTP functions and leaves the OWA
and mobile to the imagination. I've been investigating port forwarding but
I'm not sure what ports and the powers that be have stated they don't want
to do it.

I'm open to suggestions on the best means to set this up.

Jerry M. Wright
jwright@jhmi.edu

Re: OWA and Mobile access. DMZ configuration for EX2007? by mpriem

mpriem
Wed Feb 07 09:12:42 CST 2007

An Edge transport server will not handle anything else than email
traffic, and cannot contain any other roles. Handling Client Access is
performed by the Client access server. The limititation is that the
CAS needs to be in the same AD site as the mailbox servers. You can
however publish E2K7 Client access and outlook anywhere with ISA
2006....



Re: OWA and Mobile access. DMZ configuration for EX2007? by mpriem

mpriem
Wed Feb 07 09:16:57 CST 2007

On 7 feb, 16:12, "mpriem" <s...@mpriem.com> wrote:
> An Edge transport server will not handle anything else than email
> traffic, and cannot contain any other roles. Handling Client Access is
> performed by the Client access server. The limititation is that the
> CAS needs to be in the same AD site as the mailbox servers. You can
> however publish E2K7 Client access and outlook anywhere with ISA
> 2006....


http://technet.microsoft.com/en-us/library/30052fb9-0b08-4d74-b8c9-d635bdf4f831.aspx

http://www.msexchange.org/tutorials/Publishing-Exchange-2007-OWA-ISA-Server-2006.html