Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nicola_Papapicco
New Contributor

How To manage Exchange Server configured with role EdgeTrasport

Hello, I' m really new to fortinet world. I have some experience in managing firewalls from other vendors. For a customer I am going to replace the current firewall, MS ISA Server 2006 with a FortiGate 90D. The customer has Exchange Server with roles EdgeTransport installed on a server in DMZ and MB-CA-HT roles installed on a server in the LAN. Server are in sync thanks to firewall rules that permit traffic between them. When some years ago I deployed Exchange Server I used ISA Server mail publishing rule and Microsoft knowledgebase document to put the configuration to work. How I should manage this exchange configuration with the new fortigate? Any advice welcome Nicola
2 REPLIES 2
Rick_H
New Contributor III

EdgeTransport doesn' t need to participate in AD so its policy requirements are minimal. You' ll just need to create policies that open the few ports it needs between DMZ and Internal. According to this TechNet article the ports are TCP 50389 (LDAP), UDP 50636 (sLDAP), and TCP 25 (SMTP). You' d need another policy to open TCP 25 from WANx to DMZ as well. It seems pretty straight forward.
Nicola_Papapicco
New Contributor

Great! It' s just what I did in ISA Server with the current configuration. Thanks
Labels
Top Kudoed Authors