Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-22-2009, 11:50 AM
Project Contributor
 
Posts: 252
Default Zimbra inside a LAN

Hi guys,

I'm trying to make a client of me switch from exchange to zimbra.

I had a chat with the tech guy this morning and he mentioned that he wants the mail server inside their lan network and have a relay on their DMZ for security reasons. I don't like this architecture but i offeref to do some research on this.

Any thoughts? Smth you guys would recommend? What are the +/- of doing this?

Thanks!
Reply With Quote
  #2 (permalink)  
Old 04-22-2009, 12:26 PM
Moderator
 
Posts: 872
Default

We've been running Zimbra in the configuration you've described for a few years now without any issues. Before moving to Zimbra we had the email gateway setup and left it in place after the move. The gateway is using a lot of the same software that Zimbra uses (postfix, amavisd, spamassassin, clamav), so in some ways it is probably redundant. I still kind of like the extra layer of security that is provided.

I don't know for sure, but I think this would be a somewhat common setup with Zimbra. What are your concerns?
Reply With Quote
  #3 (permalink)  
Old 04-22-2009, 12:40 PM
Project Contributor
 
Posts: 252
Default

The gateway will require to know which users exist or not for the domain, right? Otherwise it will relay non existent users.

Are you using zimbra also as a gateway? Or are you using smth custom?

Thanks,
Reply With Quote
  #4 (permalink)  
Old 04-22-2009, 12:48 PM
Project Contributor
 
Posts: 252
Default

The thing i don't like of having the mail server on the lan is that if any pc gets infected by a virus it may attack the mail server and start sending spam (lan is on the trusted networks).

The thing is that i need a way to demostrate it to this guy so any other vulnerabilities will be cool.

Thanks!
Reply With Quote
  #5 (permalink)  
Old 04-22-2009, 02:46 PM
Moderator
 
Posts: 872
Default

Quote:
The gateway will require to know which users exist or not for the domain, right? Otherwise it will relay non existent users.

Are you using zimbra also as a gateway? Or are you using smth custom?
Our Internet email gateway does not know about all our users. You are right; it does relay non-existent users. But then they are rejected by the Zimbra server. Net effect is the same.

The email gateway is not running Zimbra. Like I said, it was setup prior to us using Zimbra and we kept it in place. I used one of the many "recipies" out there on the 'net for setting up an Internet email gateway using open source tools.

Quote:
The thing i don't like of having the mail server on the lan is that if any pc gets infected by a virus it may attack the mail server and start sending spam (lan is on the trusted networks).
Oh, so now I see. You are concerned about having the email server on your LAN for security reasons. I thought you were more concerned with having the extra gateway server to worry about. Some of your concerns here are probably valid. We did run into a situation similar to what you are describing with the virus. I'm not really sure it would have been avoided if the Zimbra server wasn't on our LAN.
Reply With Quote
  #6 (permalink)  
Old 04-25-2009, 12:25 AM
Special Member
 
Posts: 137
Default

You can use zimbra proxy (nginx proxy in fact) to do this.
Just put it in you dmz, then migrate your zimbra server(s) in the lan.

+ Your zimbra server containing your precious data (e-amil and so on) is not directly visible from outside, where ugly bad hackers lives That's the main purpose of a reverse proxy.

+ You don't charge your firewall with traffic when users from lan want to access zimbra. (you'll have to create a "fake" zone in your internal dns to redirect lan users to the lan ip of you zimbra server)

- You have another zimbra server in your architecture (zimbra proxy)
Reply With Quote
  #7 (permalink)  
Old 04-25-2009, 12:46 AM
Project Contributor
 
Posts: 252
Default

Thanks Nozil, that will work perfectly. Can i have zimbra's antispam and antivirus running on the proxy server?

Cheers!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.