Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 6
lượt xem 4
download
Module 6: Integrating ISA Server 2004 and Microsoft Exchange Server. This module explains how Microsoft Exchange Server is a critical network service that is virtually always accessible from the Internet and how ISA Server 2004 can be used to provide security for Exchange Server and for securing client connections to Exchange.
Bình luận(0) Đăng nhập để gửi bình luận!
Nội dung Text: Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 6
- Module 6: Integrating ISA Server 2004 and Microsoft Exchange Server
- Overview Issues in E-Mail Security Configuring ISA Server to Secure SMTP Traffic Configuring ISA Server to Secure Web Client Connections Configuring ISA Server to Secure Client Connections
- Lesson: Issues in E-Mail Security E-Mail Security Threats Overview E-Mail Access Using Web Clients E-Mail Access Using Outlook Clients E-Mail Access Using POP3, IMAP4, and NNTP Clients SMTP Protocol-Level Exploits Unwanted and Malicious E-Mail How ISA Server 2004 Secures Exchange Server
- E-Mail Security Threats Overview Ensuring the security of e-mail includes: Ensuring that all e-mail client connections to the e-mail server are secure Protecting the e-mail servers from SMTP exploits Preventing unwanted or malicious e-mails from entering the organization’s network
- E-Mail Access Using Web Clients Outlook Mobile Access ActiveSync XHTML, cHTML, HTML Enabled Mobile Devices Exchange Front-End Server Wirele ss Netwo rk ISA Server Exchange Back-End Servers Outlook Web Access
- E-Mail Access Using Outlook Clients Exchang Port 135 and dynamic e ports Front- End Outlook RPC Server Connections ISA Serve Outlook RPC Exchang r over HTTP e Connections Back- End Port 80 or 443 Servers
- E-Mail Access Using POP3, IMAP4, and NNTP Clients Exchang Port 110 or 995 Port 25 e Front- End POP3 Server Connections ISA Serve r IMAP4 Exchang Connections e Back- End Port 143 or 993 Port Servers 25
- SMTP Protocol-Level Exploits SMTP servers can be vulnerable to: Buffer overflow attacks when SMTP commands are sent with more than expected data, causing memory buffer overflows Mail relay attacks when an SMTP server is used to forward unwanted e-mail to Internet recipients SMTP command attacks where SMTP commands are used to compromise the server or gain information about the server or recipients on the server
- Unwanted and Malicious E-Mail Unwanted e-mail is unsolicited commercial Consumes e-mail that: server and network resources Reduces user productivity and increases administrative effort Can be filtered using an application-level filter May result in exposure to legal liability Malicious e-mails contain viruses or worms that: Damage data or computers or consume network and computer resources Increase administrative cost and effort Increase the risk of an information leak
- How ISA Server 2004 Secures Exchange Server Mail publishing Exchang wizards e Secure access Front- for Web End clients Server Secure ISA access Exchang Serve for Outlook e r clients Back- End Servers Filtering unwanted e- mail SMTP command filtering
- Lesson: Configuring ISA Server to Secure SMTP Traffic How ISA Server Secures SMTP Traffic How to Configure ISA Server to Secure SMTP Traffic How SMTP Filtering Works How to Configure the SMTP Application Filter How SMTP Message Screener Works How to Implement SMTP Message Screener Integrating ISA Server and Exchange Server to Secure SMTP Traffic
- How ISA Server Secures SMTP Traffic Use Mail Publishing Wizard to publish Exchang SMTP Servers e Front- End Server Use SMTP application filter to filter SMTP ISA commands Serve Exchang r e SMTP Back- End Serve Servers r Use SMTP message screener to filter unwanted e-mail
- How to Configure ISA Server to Secure SMTP Traffic To configure ISA Server to secure SMTP Configure MX records on the Internet traffic: 1 servers to refer to the computer running ISA Server Use the Mail Server Publishing Wizard 2 to publish the SMTP server Configure the internal SMTP servers 3 as SecureNAT clients Configure an access rule for internal 4 SMTP servers to send e-mail to the Internet Configure DNS so the Internal SMTP 5 servers can resolve Internet host names
- Practice: Publishing an SMTP Server Creating the Internet DNS records Configuring a new SMTP mail server publishing rule Configuring outbound SMTP traffic Gen-Web-01 Testing SMTP traffic flow Den-ISA-01 Internet Den-Msg-01Den-DC-01
- How SMTP Filtering Works Is the … Exchang Command allowed? e Command length allowed? Front- End Server SMTP Serve r ISA Exchang Serve EHLO contoso.com e r Mail from: Ben@contoso.com Back- End Rcpt to: Jay@cohovineyard.com Servers Data
- How to Configure the SMTP Application Filter
- How SMTP Message Screener Works Install Message Screener Is the … Source Host allowed? IIS 6.0 Source Domain allowed? With Attachment allowed? SMTP Service Keyword blocked? SMTP Serve r ISA Exchang Serve e r Back- End Servers
- How to Implement SMTP Message Screener To implement SMTP message screener: Install the SMTP service on an IIS 5.0 or 1 IIS 6.0 server Install the SMTP message screener on 2 the IIS server Configure an SMTP mail server 3 publishing rule that publishes the SMTP server running message screener Configure the message screener 4 settings on the SMTP filter
- Practice: Implementing SMTP Message Screener Install the SMTP service on the computer running ISA Server Install the SMTP message screener Configure the SMTP message screener Test the SMTP message Gen-Web-01 screener Den-ISA-01 Internet Den-Msg-01Den-DC-01
- Integrating ISA Server and Exchange Server to Secure SMTP Traffic On the computer running ISA Server. This You can is option deploy message the easiest screener: to configure but least secure On an IIS server in the internal or perimeter network. Using a server in the perimeter network is most complicated to configure, but most secure To filter only inbound messages. Configure ISA Server to publish the message screener server, and configure access rules for the internal SMTP servers to send e-mail to the Internet To filter inbound and outbound messages. Configure ISA Server to publish the message screener server, and configure the internal SMTP servers to route messages to the message screener server
CÓ THỂ BẠN MUỐN DOWNLOAD
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 2
45 p | 39 | 4
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 3
36 p | 41 | 4
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 5
36 p | 50 | 4
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 10
41 p | 41 | 4
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 8
38 p | 47 | 4
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 9
25 p | 56 | 4
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Introduction
12 p | 47 | 3
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 12
10 p | 46 | 3
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 11
31 p | 44 | 3
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 7
23 p | 50 | 3
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 4
31 p | 35 | 3
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 1
15 p | 53 | 3
-
Course 2824B: Implementing Microsoft internet security and acceleration server 2004 - Module 13
10 p | 37 | 3
Chịu trách nhiệm nội dung:
Nguyễn Công Hà - Giám đốc Công ty TNHH TÀI LIỆU TRỰC TUYẾN VI NA
LIÊN HỆ
Địa chỉ: P402, 54A Nơ Trang Long, Phường 14, Q.Bình Thạnh, TP.HCM
Hotline: 093 303 0098
Email: support@tailieu.vn