Hey all,

We are running Exchange 2000/Outlook 2000 in Corporate/Workgroup Mode. The 
Exchange servers are outside the NG FP3 and the Outlook clients are all inside.

I have setup a rule to allow the internal network to access the Exchange 
servers using the "MSExchange" built-in Group under "Services". The logs 
promptly fill up with each client connecting to the Exchange server using 
135/tcp and then some random tcp-port. Life is good.

However, I then see a whole bunch of denied connections from the Exchange 
server to the Outlook clients on random udp ports. I am puzzled: Isn't the 
return communication supposed to be in the same state as the outbound traffic? 
Why are these connections being denied? Do I have to setup another rule that 
basically allows the Exchange servers to communicate on all high ports (>1024) 
to the Outlook clients?

Without hard-coding the Exchange servers to talk back in a narrow range of 
ports (we don't have access to those servers), how have you guys been able to 
enable this Exchange-Outlook communication through the FW1?

Thanks!
-Kiat

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to