I am seeing some chatter on the newsgroups and web forums as to what ports to open up on a firewall to allow the Client Access and Hub Transport server roles to be placed in the perimeter / DMZ network. Do not do this. Microsoft neither recommends this configuration nor is it supported. You have to open up too many ports on the firewall. If you need to terminate external HTTP/HTTPS connections from the Internet in your DMZ, put a reverse proxy there. Squid is a good freebie that runs on Linux, ISA Server, and BlueCoat are also good solutions.
read more »
Be the first to post a Comment!