Hi All,

Question being asked about Microsoft Exchange here due to the packets you
may have noted being blocked by the firewall, so anybody who has experienced
the same traffic pattern, please let me know.

Note in the firewall log, burst of traffic from our Exchange servers being
sent to/from arbitrary ports to external IP addresses. Packets
dropped/rejected, as they should be as it is denied unknown/denied
protocols.

The scenario is that we run WebOutlook services, and I suspect that the
Exchange servers are trying to communicate directly with the system with the
client running the WebOutlook URL loaded in their browser. This rejected
traffic does not impact any functionality. Client on Internet communicates
with HTTP front-end on DMZ, which in-turn communicate with Exchange server
on secure internal network.

However I want to how to terminate this arbitrary traffic, so it doesn't
show up repeatedly in the logs....but without using any masking rules which
don't block. ( I haven't been able to find a thing ay Microsoft which points
to any issues)

So upshot, anybody experienced this behavior with WebOutlook and traffic
attempting to traverse security points?

Thank you for your time.

Andrew Jamieson

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to