Gary Maltzen wrote:
> 
> Mikael said:
> >In short: PPTP is not an alternative here.
> 
> I figured opening a SINGLE (pair) through the firewall 
> (**between two specific servers**) might be somewhat more 
> "controllable". It seemed to me a simpler solution than 
> restricting the ports used in the OWA/Exchange communication.

Mmmmm no. We don't trust the outer server to talk to the inner server in
an uncontrolled fashion -- that is exactly the path of compromise that we 
are trying to patch up. PPTP would allow unrestricted communication.

-- 
Mikael Olsson, EnterNet Sweden AB, Box 393, S-891 28 �RNSK�LDSVIK
Phone: +46 (0)660 29 92 00         Direct: +46 (0)660 29 92 05
Mobile: +46 (0)70 66 77 636        Fax: +46 (0)660 122 50
WWW: http://www.enternet.se/       E-mail: [EMAIL PROTECTED]
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to