Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Connect to Exchange From outlook Across PIX

I am attempting to configure a PIX 520 to support connections from a low security zone to high security zone inbound to a exchange server from outlook.

I am using the NAT 0 options and have the no problem pinging, hitting the web interface on the same box, or using an IMAP client. I understand that exchange is pretty unique in its use of prots and i have configure dthe

establishes tcp 135 permitto tcp 1024-65535 option but i am drawing a blank. Connectivity still fails. Any suggestions whould be great. Thanks a bunch

3 REPLIES
New Member

Re: Connect to Exchange From outlook Across PIX

We have an Exchange server and our clients connect through the PIX using Outlook.

What we did -

First, follow this link for instructions on assigning static ports to Exchange for use with client connections

http://support.microsoft.com/default.aspx?scid=kb;en-us;155831

Then, obviously, setup a static mapping from the high security interface to the low security interface for the Exchange server.

Setup ACLs for port 135, and the two ports you assign via the registry per the above link

Finally, and this is very important, make sure your clients have a means for resolving the Exchange servers host name to an ip address. With Outlook, even if you first enter the IP address into the configuration it automatically converts this to the Hostname upon first connection. You can either use lmhosts files, hosts files, or make sure your mail server has a DNS entry in your clients dns server and the client is properly configured for appending the domain suffix to DNS queries for your domain.

Hope this helps.

~rls

Silver

Re: Connect to Exchange From outlook Across PIX

Is there a reason you aren't doing this through a vpn? '

http://www.securityfocus.com/archive/1/296114

MS's RPC service stuff on port 135 has had a miserable security history.

New Member

Re: Connect to Exchange From outlook Across PIX

VPN's nice, but when our consultants are behind a client's firewall it's not always a viable option. And unfortunately Exchange's webaccess leaves a lot to be desired.

There are some other options, like using a relay server. But our current setup has been working great for the past two years without a hitch.

~rls

99
Views
0
Helpful
3
Replies