<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exchange 2016 Mailbox Servers in the DMZ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137064#M47737</link>
    <description>&lt;P&gt;Has anyone had any issues deploying Exchange 2016 servers in a "DMZ" behind the Palo Alto firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft does not support this configuration and their preferred architecture is to put the Exchange servers in the internal network.&amp;nbsp; Because these Exchange servers are public facing, we are pushing to have the servers set up in our DMZ.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 19:46:00 GMT</pubDate>
    <dc:creator>jambulo</dc:creator>
    <dc:date>2017-01-11T19:46:00Z</dc:date>
    <item>
      <title>Exchange 2016 Mailbox Servers in the DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137064#M47737</link>
      <description>&lt;P&gt;Has anyone had any issues deploying Exchange 2016 servers in a "DMZ" behind the Palo Alto firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft does not support this configuration and their preferred architecture is to put the Exchange servers in the internal network.&amp;nbsp; Because these Exchange servers are public facing, we are pushing to have the servers set up in our DMZ.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 19:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137064#M47737</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2017-01-11T19:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2016 Mailbox Servers in the DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137103#M47743</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What you are attempting to do is the right approach, in my opinion. The logs are your best friend when it comes to this. Check for any traffic not getting to where it needs to go. I always put a DENYALL rule as the last rule so I can see clearly if it is being hit by any traffic and adjust or add rules above it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 22:40:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137103#M47743</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-01-11T22:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2016 Mailbox Servers in the DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137238#M47769</link>
      <description>&lt;P&gt;Microsoft doesn't support it because it's a time consuming thing to setup; as long as you have the time to monitor the logs and open the ports that are actually needed you really aren't going to run into any issues. I'm actually not sure why Microsoft really discorages this configuration, I assume because it causes an issue with setting up autodiscover if you don't have the right ports open?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2017 17:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137238#M47769</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-12T17:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2016 Mailbox Servers in the DMZ</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137458#M47806</link>
      <description>&lt;P&gt;I'm sure they advise against it because they don't want to have their support folks or system level contractors have to worry about something obstructing access.&amp;nbsp; There's also the argument of local Windows firewalls.&amp;nbsp; I personally disagree with the idea of not putting it a segregated environment--especially because as of 2016 Outlook Web Access also runs on the same server.&amp;nbsp; As long as the correct ports (and app-ids) are defined it should work.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 21:41:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exchange-2016-mailbox-servers-in-the-dmz/m-p/137458#M47806</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-01-13T21:41:34Z</dc:date>
    </item>
  </channel>
</rss>

