Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-07-2008, 10:45 PM
Advanced Member
 
Posts: 193
Default External Users of Zimbra to only use VPN

Hi All,

We are looking into making all our users, when ever they are on the road, to access their e-mail only using VPN.

I have been looking around the forum for post on similar item but have not found something (or maybe I missed it).

What do we need to do so that users will not be able to access https://mymail.domain.com from any internet connection? And in order for them to access it, they have to do VPN.

I would really appreciate for any feedback or if you can point me somewhere in the forum that have the same requirements.

Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 09-11-2008, 04:23 AM
Advanced Member
 
Posts: 193
Default

Any idea on this one please? Any kind soul out there?
Reply With Quote
  #3 (permalink)  
Old 09-11-2008, 04:26 AM
Moderator
 
Posts: 7,911
Default

Do you not have a firewall in front of your ZCS installation ? If you do then why not just allow the VPN IP block access to port 443 on your server ?
__________________
Reply With Quote
  #4 (permalink)  
Old 09-11-2008, 05:11 AM
Advanced Member
 
Posts: 193
Default

Thanks Uxbod. But can you help understand further your suggestion?

And yeah, really thanks!
Reply With Quote
  #5 (permalink)  
Old 09-11-2008, 05:19 AM
Intermediate Member
 
Posts: 21
Default or do it with DNS

... Firewall restricting/preventing access from outside to your Zimbra box's IP port 443 is (probably) best, but you could probably use DNS, and simply not make the zimbra's IP resolveable via public DNS servers, keep it's record only in your company's internal DNS.

bottom line though. You should have your mailserver in a DMZ (DeMilitarized Zone) behind a firewall.

please post more details of how your servers access the net / how the net accesses your servers so that we can provide better suggestions.

Ciao
__________________
Current specs:
Updated 7 NE on Ubuntu 10.04 KVM virtual machine.
on Dell server hardware.

6.08_GA on Ubuntu 10.04

Previously:
Release 5.0.2_GA UBUNTU FOSS edition
on ubuntu 7.10 (gutsy) 1Gig RAM
inside VirtualBox virtual machine host
intel P dual-core. 3Gig Ram

Release 4.5.0_GA_612.UBUNTU6 UBUNTU6 FOSS edition
AMD Athlon XP 2100+ 1.7Ghz, Ram 512MB, HDD: 40Gig

Release 3.1.4_GA_518.FC4_20060626144747 FC4 FOSS edition
Pentium 4, 3.0Ghz, Ram:1Gig, HDD: 40Gig
Reply With Quote
  #6 (permalink)  
Old 09-11-2008, 07:32 AM
Outstanding Member
 
Posts: 684
Default

Accessing your mail server across an SSL connection will give you the same security as through your VPN.

However, I add my private LAN IP of my mail server to the HOSTS file of my branch offices and laptops. The VPN client on the laptops are set to auto connect when the PC tries to access any IP's that exists on my private home office LAN. So when they access the mail server it gets the IP from the hosts file which in turn automatically makes a VPN connection to the home office. You could set the VPN client to manually connect and make the VPN connection first, but that seemed to confuse some users.
Reply With Quote
  #7 (permalink)  
Old 09-12-2008, 09:36 PM
Advanced Member
 
Posts: 193
Default

Thanks for the reply guys. :-) Really appreciate your inputs.

To answer apatosaur.9, my zcs server is behind a UTM and not in DMZ. It's part of the private LAN.

Somehow it looks like this:

Internet--->UTM---->ZCS---->Users

And with this setup, users can access their mails from anywhere with internet connection via https.

We somehow want to make it like this:

External Users-->VPN--->Internet--->UTM--->ZCS--->Internal Users

What we want to happen is for the users to make use of VPN in order to get their mails. Not just ordinarily from any Internet connection.

The reason behind this is to discourage the users from using Internet shops/cafes to access their mails, since alot of these internet shops have keyloggers in their workstations. Several of our user accounts have been already compromised by this type of access from Internet shops/cafes.

If there will be a better suggestion rather than just using VPN, it would be highly appreciated.

Thanks in advance.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.