RE: Re: gpl digest, Vol 1 #1264 - 1 msg
"Alistair Francis" <ali-QGBN+/qDeXgGFrCMPLEOK/d9D2ou9A/[email protected]> Mon, 15 Nov 2004 09:22:19 +0200
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Richard, FYI, SW won't block users on GREEN from accessing a mail server on ORANGE. Outbound traffic from GREEN is not blocked (by default). Therefore, speed should not be an issue. However, I'm guessing that you're running one box as both a PDC and Exhange? You may have issues with the PDC being on ORANGE. Rgds, Alistair Francis Systems Administrator Comm Express Services SA (PTY) LTD TEL: +27 (0)11 475-5567 FAX: +27 (0)11 475-6238 CELL: +27 (0)82 608-0181 The information contained in this electronic mail message is confidential to the Matragon group of companies and may enjoy legal privilege. The contents are intended solely for the addressee and access thereto by anyone else is unauthorised. Should you not be the intended recipient, kindly delete the message and inform us. Any disclosure, copying or distribution is prohibited and may be unlawful. Please also note that any action taken, or omitted to be taken in reliance on the information contained herein is done at your own risk. -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of Richard Doiron Sent: 13 November 2004 17:16 To: Drew S. Dupont; [email protected] Subject: Re: [gpl] Re: gpl digest, Vol 1 #1264 - 1 msg Hi all, I forgot to mention that the Exchange box is MS small business server. I9m not sure of the complications of drive mapping, active directory, and domain logins from the green network when the server is positioned on the orange network. Users have a low tolerance for slow logins, drives that don9t map properly etc. >From the various responses so far, this looks like an internal/external dns hack solution. I9ll post my results in a few days. Thanks all for the guidance. Richard -- Richard Doiron (Voice 613-723-3300 ext 2224 Cell 613-295-3912 2Fax 613-723-3011 MSN Messenger [email protected] 6 Antares Drive, Phase I, Suite 104 Ottawa, Ontario, Canada K2E 8A9 http://www.cngglobalservices.com 2We deliver what we promise.2 For the latest CNG News click http://www.cngglobalservices.com/news.htm For the latest Hot Opportunities click http://www.cngglobalservices.com/hot_opps.htm This email transmission is directed in confidence to the person(s) named above, and may not be otherwise distributed, copied or disclosed. If you have received this e-mail transmission in error, please notify the sender immediately by telephone and delete it without making a copy. Due to the inherent risks associated with the Internet, we assume no responsibility for unauthorized interception of any Internet communication with you or the transmission of computer viruses. Thank you for your co-operation. -- From: "Drew S. Dupont" <dsdupont-cRNsNxxcKCstbC/[email protected]> Date: Sat, 13 Nov 2004 09:05:57 -0500 To: <[email protected]> Subject: [gpl] Re: gpl digest, Vol 1 #1264 - 1 msg >Message: 1 >Date: Fri, 12 Nov 2004 17:52:02 -0500 >From: Richard Doiron <[email protected]> >To: <[email protected]> >Subject: [gpl] Question about MS Exchange and Smoothwall Express > >Hi, > >I have a need to set up Exchange 2003 on a private lan with users who need >access to the Exchange server from both from the private lan and the >internet. I have port forwarding set up so that a user can access the >Exchange server fine from the internet using the public address of the >Smoothwall. Similarly, users on the private lan get their Exchange fix using >the private address of the exchange server. > >The problem comes in with laptop users. If they set up their Exchange >account to use the private lan address, when out of the office nothing >works. If they set up the Exchange account to use the public address of the >Smoothwall, being out of the office works, but when inside, the Smoothwall >is discarding all packets (Martians?). > >The old setup used a Symantec Firewall VPN 200r and it worked in this >configuration. > > Setting up an Orange segment is not feasible as the client only has one box >to run server and exchange. > >Any help would be appreciated. > >Richard > >--__--__-- Add the external IP and/or name (depending on which, if not both, are setup for use) to the SW's /etc/hosts file and restart the DNS proxy (just restart SW or run a kill and dnsmasq with the right options). That way, if the laptop users try to get to the server suing the public IP outside your LAN, it works, and if they try inside the LAN, it will resolve to the local IP. This will only work if SW is the DNS server (or in the DNS call chain). If not, then add it to the local DNS server the laptop users get their DNS from. You would add something like the following to the hosts file if you do it in SW: <internal ip><tab><external ip> <internal ip><tab><hostname> NetWhiz -- ---------------------------------------------------------------------------- -------------------------- Drew S. Dupont dsdupont-cRNsNxxcKCstbC/[email protected] AIM: NetWhizOne FWD #: 271144 YIM: dsdupont ---------------------------------------------------------------------------- -------------------------- _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall [demime 1.01a removed an attachment of type image/png which had a name of image.png] _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall