Best Practice on Not Exposing your internal FQDN to the outside world

Exchange server 2010, sits in DMZ, internet facing. The server is currently using the Default Receive Connector. This exposes the internal fqdn to the outside world (ehlo). Since you should not (can't) change the FQDN on your Default Receive connector, what
is the best practice here?
The only solution I can see is the following:
1. Change the Network on the Default Receive Connector to only internal IP addresses.
2. Create a new Internet Receive Connector port 25 for external IP addresses (not sure what to put in Network tab?) and use my external FQDN for ehlo responses (e.g. mail.domain.com)
3. What do I pick for Auth and Permissions, TLS and Annoymous only?
Michael Maxwell

Yes, it fails PCI testing/compliance. I shouldn't be able to see my internal server and domain. I understand that is the recommendation, but my client doesn't want to host in the cloud or go with a Trend IHMS (trust me I like that better, but its
not my choice). I have to work with the deck of cards dealt to me. Thanks, just want a solution with what I have now.
Michael Maxwell
Understand. I wont go into the value of those tests  :)
If the customer is really concerned about exposing the internal name, then create a new receive connector with a different FQDN  ( and corresponding cert)  for anonymous connections as you mention above. Know that  it also means internal clients
can connect to the server on port 25 as well if you dont have the ability to scope to set of ip addresses ( i.e. a SMTP gateway).
The internal names of the servers will also be in the internet headers of messages sent out:
http://exchangepedia.com/2008/05/removing-internal-host-names-and-ip-addresses-from-message-headers.html
http://www.msexchange.org/kbase/ExchangeServerTips/ExchangeServer2007/SecurityMessageHygiene/HowtoremoveinternalservernamesandIPaddressesfromSMTPheaders.html
Twitter!:
Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

Similar Messages

  • How to expose a web service to the outside world?

    Hello,
    i have created a Web service from a Session bean and successfully published it on one of my UDDI registries using the Admin tool.
    At this point, what do I need to do further in order to expose this Web service not just in our LAN but to the outside world?
    Roy

    Offcourse it should be published at UDDI.
    Four play  key roles in Web services: Universal Description, Discovery and Integration (UDDI), Web Services Description Language (WSDL), Web Services Inspection Language (WSIL), SOAP, and Web Services Interoperability (WS-I).
    The UDDI specification defines open, platform-independent standards that enable businesses to share information in a global business registry, discover services on the registry, and define how they interact over the Internet.
    See this link too:
    http://help.eclipse.org/help32/index.jsp?topic=/org.eclipse.jst.ws.consumption.ui.doc.user/concepts/cwsdlud.html
    Regards, Suresh KB

  • TS2690 we could not complete your itunes store request. the network connection could not be established

    we could not complete your itunes store request. the network connection could not be established

    Hello ,
    you can try to sign out of your apple account then sign in again.

  • TS3297 i can no longer connect to itunes. a message comes up "we could not complete your itunes request. The itunes store is temporarily unavailable. please try again later. but when i use a different acct. it goes through right away . why did this start

    i can no longer connect to itunes. a message comes up "we could not complete your itunes request. The itunes store is temporarily unavailable. please try again later. but when i use a different acct. it goes through right away . why did this start happening?

    I don't know - but I am having the same problem and have not had any useful help from Apple Support.  Everything they told be to do has been done and it hasn't fixed the problem.

  • I'm trying to download the new MacOS. I keep getting a dialog that says: "We could not complete your purchase" and then " The product distribution file could not be verified. It may be damaged or was not signed." any ideas?

    I'm trying to download the new MacOS. I keep getting a dialog that says: "We could not complete your purchase" and then " The product distribution file could not be verified. It may be damaged or was not signed." any ideas?

    I went to Purchases and it worked from there having had the same problem you describe.

  • HT201364 i tried upgrading my macbook but troublesome to upgrade. It appears "we could not complete your purchase". besaide says, the product didtribution file could nto verified and may be damaged or not signed. in view of the above, kindly advise me.

    i tried upgrading my macbook but troublesome to upgrade. It appears "we could not complete your purchase". besaide says, the product didtribution file could nto verified and may be damaged or not signed. in view of the above, kindly advise me.

    Did anything download or are you getting this when trying to install?
    Try booting into the Safe Mode and do the installation there.
    Safe Mode
    Safe Mode - About
    There are various suggestions in this discussion. You might start with the last post first.
    https://discussions.apple.com/thread/4136660?start=30&tstart=0

  • Expose services on XI to the outside network

    Hi,
    We have a requirement that the web service hosted on xi would be invoked by another system which is outside the client's network. Although I will be using https in this case, still the client is apprehensive about opening the port of SAP XI to the outside world.
    Should we use a middleware system between XI and the outside network
    OR
    Expose the XI webservices over HTTPS?
    Please suggest the correct option.
    regards,
    Piyush

    Hi,
    Another possibility is thru the DMZ, there you will publish a web service to receive the data and later that web service will be mapped to the PI web service.this is manage by network administrator not in pi configuration.
    other possibility is ussing HTTPS or digital signature (RSA,3DES).
    Thanks
    Rodrigo

  • Not a question, but a suggestion on updating software and best practice (Adobe we need to create stickies for the forums)

    Lots of you are hitting the brick wall in updating, and end result is non-recoverable project.   In a production environment and with projects due, it's best that you never update while in the middle of projects.  Wait until you have a day or two of down time, then test.
    For best practice, get into the habit of saving off your projects to a new name by incremental versions.  i.e. "project_name_v001", v002, etc.
    Before you close a project, save it, then save it again to a new version. In this way you'll always have two copies and will not loose the entire project.  Most projects crash upon opening (at least in my experience).
    At the end of the day, copy off your current project to an external drive.  I have a 1TB USB3 drive for this purpose, but you can just as easily save off just the PPro, AE and PS files to a stick.  If the video corrupts, you can always re-ingest.
    Which leads us to the next tip: never clear off your cards or wipe the tapes until the project is archived.  Always cheaper to buy more memory than recouping lost hours of work, and your sanity.
    I've been doing this for over a decade and the number of projects I've lost?  Zero.  Have I crashed?  Oh, yeah.  But I just open the previous version, save a new one and resume the edit.

    Ctrl + B to show the Top Menu
    View > Show Sidebar
    View > Show Staus Bar
    Deactivate Search Entire Library to speed things up.
    This should make managing your iPhone the same as it was before.

  • Best practice to NOT transport reports?

    Hi,
    I was once told that it was best practice NOT to transport reports, templates, process chains and packages. (BW 3.5). These objects changed so often that you would spend to much time transporting. Now I have heard from others that it is usual to transport these things. What is your opinion on this?
    Regards Silje

    Hi,
    Test queries for the user and the process chains which are needed to be created and not affecting any data loads and need not be tested in test system like deleting the PSA....these kind of objects are directly created in production and need not be transported again.
    But even in the case of process chains changes are not supposed to be done directly in production.
    But SOX compliance and SAP says that every object should be first changed into development and transported till production...and as you said its usual to do changes to these objects and transport them to production.
    Thanks
    Ajeet

  • We could not complete your itunes store request. the network connection timed out

    Can anyone help me with this message? We could not complete your itunes store request. The network connection has timed out.

    im not sure how this works but i seem to be getting that same message matter fact my ipad 1 went into recovery mode and all i was doing was playing a game and it showed that i had to connect to itunes did that and it said it had to update and i did that and upon the update it showed network connections timed out. tech support said to turn off firewall and anti virus and try again did that and it did the same thing. and im not sure what else im supposed to do. i can get it fixed threw best buy but the thing is paying 30 bucks ***** and you know i souldn't have to pay if itunes would fix there problem it's not my rouder and it's not my internet cause i have went to other peoples homes and tryind and get the sam ething so it has to be apple or itunes not sure which but wish they would fix the problem

  • Please help me to fix the problem of my iphone 3gs, its says no service and could not activate your phone...the server is temporrili unavailable,try to connect it to itunes or wait a few minutes...i tried maany times but it does'nt work..please help me

    had a problem with my iphone 3gs.it came from recovery mode,after it it says no service,then activate your iphone..then i follow the steps appeare in the screen..after it it sys could not activate your phone.the server is temporrily unvailable or try to connect to itunes..I tried it many times since january 30 2013 night time.until now it does'nt work...how can u help me to fix my iphone..thanks

    so what cn u suggest to do to operate again my phone..

  • We could not complete your itunes store request. the network connection was reset.

    When I try to play the movie I rented it says this: "We could not complete your itunes store request. The network connection was reset. Make sure your network connection is active and please try again." My connection is fine, how do I fix this?

    The latest message is: 'We could not complete your iTunes Store request. The network connection was reset.'
    In between, I got a messge about verifying my payment method. When I tried to submit the details, I kept getting a mmessage stating that my payment method was declined (my card is not near it's expiration date, and works fine).
    Argh!

  • Getting "Could not complete your request" error all the time

    Whenever I try to do anything in Fireworks CS6 (CC desktop version) I get the error message "Could not complete your request. An error occurred".  The only exception is when I try to preview an image I get "Could not render the database. An error occurred"
    This literally happens with any action, from opening a file to changing any attribute of an object (e.g. colour, position, size).  Try to draw a new object - same error.  Delete one - same error.
    Weirdly it does seem to complete the action after I "Ok" the error message.
    Any ideas? 
    I am running this on Mac OSX 10.9.1 on a pretty new MacBook Pro.  I've checked for updates and I'm running the latest version.  (I'm running the trial version, as I am trying to decide whether or not to switch over to CC from my desktop apps, but I would hope it is the same as the full commercial version)

    For me the Fireworks stopped when it got to "Intializing Tab Windows", then a crashed and  displayed "Could not complete your request. an error occurred" and would never load. Basically dead. I couldn't use it at all. My whole workfow came to a stand still.Fireworks-Error.jpg
    BACKGROUND
    Just before this happened, I was trying a new feature from within Dreamweaver. While inside Dreamweaver, I could double-click an image file and it opened in my Fireworks to be edited. I thought . . . Wow, this is really cool. I edited that image and closed it and continued on my work. Since then, that "Connection" between applications has become permanent. Fireworks "THINKS" it is still connected to Dreamweaver. Later Fireworks would NOT open/load at. I would always get the above error.
    PARTIAL SOLUTION
    BTW: I had to do this twice, because the first time, I missed a file somewhere.
    I had to completely uninstall all ADOBE applications. I mean everything! I had CS3 & CS4 and Adobe Readers on my system.
    Since I'm on the mac, I went through the "Application Support" both user and system and the "Preferences" for both user and system and deleted everything that had either "adobe" or "macromedia" in it. There was also a file in the "Launch Agent & Daemons".
    I emptied the trash and did a power off restart. Then I reinstalled CS6. Now Fireworks at least loads and I can use it again, but it still isn't the same.
    OBSERVATION
    Fireworks and Dreamweaver are still "Connected". It won't save an existing PNG file as itself, it displays an error, "That file is open in another application", which is NOT true. I have to use the "Save As" option, and use the Finder to rename that file. I also notice an extra file labeled ex:0000056 which looks like the file I tried to save.
    So at least I can use my Fireworks again although it is irritating. I don't know how to "CUT" the connection between applications. Uninstalling & reinstalling did NOT reset this, the only option left would be a backup, wipe and fresh install of my entire laptop. I just don't have time to do that right now. Hope that helps someone else.
    Arlene

  • Best Practice in regards to adding showing SkinnablePopUp from the Main application file of Mobile A

    Hello,
    I want to display a SkinnablePopUp when the user presses the back key when the current view is the first view to ask if he wants to quit.
    The logic (checking if the key pressed was the back key && the current view is the first view) is in the main application file and if those two conditions are true then the exit() method is called.
    I want to show the confirmation popup. Should I move all that in the first view mxml component or is it OK to instantiate the SkinnablePopUp in the main app file?
    Thank you.

    so do I, or did, well still do but less than before
    it seems best practice is to seperate mxml and AS3
    have a look at this
    http://tv.adobe.com/watch/max-2010-develop/flexactionscript-30-architecture-and-dependency -injection-frameworks-overview/

  • Error? We could not complete your request. What the...?

    I keep getting: "We could not complete your iTunes Store request. The network connection was refused."
    The network connection is working fine.
    My software is all up to date. I can log in to the Apple Store, access my account.
    I am logged in to iTunes and access the iTunes store but now I get the error above.
    I rebooted, repaired permissions and restarted.
    I restarted the router/Air port.
    I checked all the network preferences and renewed the DHCP lease.
    Nothing seems to work.
    Any help would be appreciated.
    Thanks...

    Hi, I am having exactly the same problem. I have 325 downloads available but every time I try and view them, itunes store logs me off with "network connection lost" I contacted itunes support and they say it must be a problem with my Mac? Problem only started when I upgraded to itunes plus. Hope someone can help?

Maybe you are looking for

  • Infinity order delays and confusion

    Hi, I am hoping someone from BT will read this post and urgently get back to me personally with an accurate and honest update on my order. I have spoken to numerous people in the contact centre's who have provided me with no confidence about my order

  • REP - 300 Error while executing report from Application

    Hi, I have report in Report Builder & for the same report form is there in Form Builder in which parameter page is designed. From application where I am calling report is internally calling form & in form Procedure Run Report is there which is callin

  • Exchange 2007 to Exchange 2010 Migration

    Hi all, I am migrating to exchange 2007 to exchange 2010 .This is not a migration data only migration like i am exporting mailboxes and importing it to new mailboxes .But email address and SAM account name will be same as per the source.Post migratio

  • Firefox will not download slottomania.

    Starting today I cannot play the Facebook game Slottomania. Firefox will download until it reaches 90% and then locks up. This has not been a problem before today. Having the problem on two different computers.

  • I can't open any Danish web sites - PLEASE HELP !!

    It's very weird, since yesterday haven't been able to open any Danish web sites. As soon as it ends with .dk it won't open the page. And seeing that my web site ends with .dk I can't get my personal e-mail to my mail program either. This is not only