Firewall Wizards mailing list archives

RE: (no subject)


From: Paul Robertson <proberts () patriot net>
Date: Mon, 25 Nov 2002 17:19:24 -0500 (EST)

On Mon, 25 Nov 2002, Don Goldstein wrote:

You can put an outlook web access server in the DMZ and the Exchange server
on your LAN.

OWA and IIS haven't exactly had the best record.  Add in password 
guessing and a pipe in to an AD or DC, and the upsides don't look all that 
attractive to me.  Now, if you're talking about a VPN'd segment off the 
DMZ, you could perhaps minimize the risk, but I don't think I'd advise my 
closest competitor to field OWA on their DMZ as a strategy without some 
more serious and direct protection.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts () patriot net      which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: