Hi,
Hopefully we are soon to be implementing Microsoft Exchange Server 2007 and ISA Server 2006 and I have a few questions about the deployment process and security etc. I currently have it in a test environment as well so I can test out any suggestions
1.) Currently there is no edge transport server and the one exchange server with the hub transport role sends and receives all mail. Is this secure? Our email is sent through a smart host which apparantly has reverse DNS enabled which adds more security IIRC?
2.) Will a 3.0GHz Xeon with 1GB RAM run exchange ok?
3.) How do I setup ISA server to route email traffic through to the exchange server? I'm assuming I need to send all traffic for port 25 on to the exchange servers internal IP address as the only access exchange has to the internet is via the ISA server.
4.) What can I do for anti-virus and anti-spam protection? I was looking at Sophos PureMessage but this doesn't support Exchange 2007 yet and it looks like exchange forefront security is the only option but I'm not sure whether this will work without the edge transport server role installed.
5.) I'm concerned about security of OWA 2007. I've been watching the demos on the microsoft site and it seems users can upload and download files from the server from home which I don't want. I also don't want public folders which allow users to place files there (?) so is there anyway to remove this apart from just unmounting the public folder database?
6.) Any advice for extra security and installaton tips would be welcome
I'm sure I'll think of some more questions soon but any help with those would be much appreciated
Thanks
Ben
Hopefully we are soon to be implementing Microsoft Exchange Server 2007 and ISA Server 2006 and I have a few questions about the deployment process and security etc. I currently have it in a test environment as well so I can test out any suggestions

1.) Currently there is no edge transport server and the one exchange server with the hub transport role sends and receives all mail. Is this secure? Our email is sent through a smart host which apparantly has reverse DNS enabled which adds more security IIRC?
2.) Will a 3.0GHz Xeon with 1GB RAM run exchange ok?
3.) How do I setup ISA server to route email traffic through to the exchange server? I'm assuming I need to send all traffic for port 25 on to the exchange servers internal IP address as the only access exchange has to the internet is via the ISA server.
4.) What can I do for anti-virus and anti-spam protection? I was looking at Sophos PureMessage but this doesn't support Exchange 2007 yet and it looks like exchange forefront security is the only option but I'm not sure whether this will work without the edge transport server role installed.
5.) I'm concerned about security of OWA 2007. I've been watching the demos on the microsoft site and it seems users can upload and download files from the server from home which I don't want. I also don't want public folders which allow users to place files there (?) so is there anyway to remove this apart from just unmounting the public folder database?
6.) Any advice for extra security and installaton tips would be welcome

I'm sure I'll think of some more questions soon but any help with those would be much appreciated

Thanks
Ben