Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Quicklist for Intradomain Communications Between Back-end and Front-end Exchange Servers

Quicklist for Intradomain Communications Between Back-end and Front-end Exchange Servers

From Jason Jones at http://forums.isaserver.org/m_2002027876/mpage_1/k...#8230;

==============================================================

Assuming FE in DMZ (domain member), BE on LAN (domain member).
Route relationship between DMZ and LAN (to allow intradomain)
Rules needed:

Front-End Exchange servers => Domain Controllers

DNS

Kerberos-Adm (UDP)

Kerberos-Sec (TCP)

Kerberos-Sec (UDP)

LDAP

LDAP (UDP)

LDAP GC (Global Catalog)

Microsoft CIFS (TCP)

Microsoft CIFS (UDP)

NTP

Ping

RPC (all interfaces)

Front-End Exchange servers => Back-End Exchange servers

HTTP

IMAP4

POP3

SMTP

Exchange Link State Routing (TCP691)

RPC over HTTP Information Store

(TCP6001)

RPC over HTTP DSReferral (TCP6002)

RPC over HTTP DSProxy (TCP6004)

Back-End Exchange servers => Front-End Exchange servers

Exchange ActiveSync Direct Push

(UDP2883)

==============================================================

HTH,

Tom

Thomas W Shinder, M.D.
Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center