Web Security Planning
Your Guide to Web Security Planning

1.JPGIt is highly recommended to avoid running all messaging components under a single server structure unless it is designed as a small departmental Exchange Server. The use of NTLM authentication in the web browser omits the need for the user to enter name and password which is a domain controller that has to be established to allow users to secure their credentials from the controller. If no pathway is provided, then NTLM has to be disabled.

The placing of a firewall between the Exchange Server and the IIS Server requires the passing of the Windows NT authentication and the Exchange RPC because there is a need for the IIS Server to connect to the Exchange Server via RPC by negotiating with the firewall.

Comments are closed.