Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-16-2010, 09:40 AM
k_k k_k is offline
Active Member
 
Posts: 40
Default Question related to DMZ

Hi,

in our current setup, mail server is connected in internal network as mentioned below :


internet request --> Firewall --> Network load balancer --> zimbra mail server.


Our client are using outlook + zimbra web mail.

below ports are open on internet :
25
465
993
995
443 --> for webmail
80 --> for antivirus update

We are supporting 1000 users with 2 different domains on single server installation...and may be in future we will migrate to multi-server installation for horizontal scalability.

Now our architecture team is suggesting to move mail server to DMZ network.
I gone through few DMZ related post in this forum..

I just need to understand is this a best practice ? And which things we need to consider as per security aspect ??

Please help.


Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 11-22-2010, 12:57 AM
k_k k_k is offline
Active Member
 
Posts: 40
Default

can anyone please guide me for the same ?
Reply With Quote
  #3 (permalink)  
Old 11-22-2010, 03:33 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by k_k View Post
can anyone please guide me for the same ?
Why not ask your architecture team why they want to do that? As far as I'm concerned putting any server in the DMZ is the same as putting it on an exposed internet IP address and totally insecure, you need to (very) carefully consider what needs to be done. If you don't know what you're doing I'd advise you to get some expert advice on setting-up a server in a DMZ.

You could also start with some articles from the internet:

SolutionBase: Deploying a DMZ on your network
+"best practice" +dmz +"mail server" - Yahoo! Search Results
__________________
Regards


Bill
Reply With Quote
  #4 (permalink)  
Old 11-22-2010, 06:19 AM
Moderator
 
Posts: 7,928
Default

If you are wishing to use a DMZ then go for a multi-server setup and proxy connections through to the backend. I am guessing your architecture team are trying to eliminate an attack vector by moving the server outside of the internal network.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.