<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Why does Microsoft not respect my firewall?</title>
	<atom:link href="http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/</link>
	<description>Because technology isn&#039;t just for geeks</description>
	<lastBuildDate>Tue, 24 Jan 2012 20:02:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
	<item>
		<title>By: George Ou</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1405</link>
		<dc:creator>George Ou</dc:creator>
		<pubDate>Mon, 02 Mar 2009 17:25:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1405</guid>
		<description>Sorry, you&#039;re right Justin.  Basically, MS is pushing us towards a reverse proxy architecture, preferably MS ISA server as far as MS is concerned.</description>
		<content:encoded><![CDATA[<p>Sorry, you&#8217;re right Justin.  Basically, MS is pushing us towards a reverse proxy architecture, preferably MS ISA server as far as MS is concerned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jmjames</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1404</link>
		<dc:creator>jmjames</dc:creator>
		<pubDate>Mon, 02 Mar 2009 15:52:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1404</guid>
		<description>As we discussed on IM, I wish this was the case. In their recent crop of products, it does not matter how many boxes you have, certain components *must* be located in the LAN and exposed over port 443. In fact, with Exchange 2007, you *cannot* put the &quot;Edge Server&quot; role on a box with any other Exchange roles installed! With OCS 2007 R2, the Web-based Communicator (Communicator Web Access) *must* be located in the LAN... and it must *not* be on the same box with the rest of the components, either! I am telling you, if there is a way to do it, it is not documented or supported.&lt;br&gt;&lt;br&gt;J.Ja</description>
		<content:encoded><![CDATA[<p>As we discussed on IM, I wish this was the case. In their recent crop of products, it does not matter how many boxes you have, certain components *must* be located in the LAN and exposed over port 443. In fact, with Exchange 2007, you *cannot* put the &quot;Edge Server&quot; role on a box with any other Exchange roles installed! With OCS 2007 R2, the Web-based Communicator (Communicator Web Access) *must* be located in the LAN&#8230; and it must *not* be on the same box with the rest of the components, either! I am telling you, if there is a way to do it, it is not documented or supported.</p>
<p>J.Ja</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Ou</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1403</link>
		<dc:creator>George Ou</dc:creator>
		<pubDate>Mon, 02 Mar 2009 15:19:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1403</guid>
		<description>You can build a dedicated Exchange gateway in the DMZ and I am pretty sure you can do the same thing for OCS.  You don&#039;t need to open directly in to your internal network.&lt;br&gt;&lt;br&gt;This is not a Microsoft problem and every Internet-enabled software in the world requires some kind of port to be open which is almost always port 443 and 80.  Because you built an all-in-one box, you have no DMZ box and you&#039;re forced to bypass the DMZ.</description>
		<content:encoded><![CDATA[<p>You can build a dedicated Exchange gateway in the DMZ and I am pretty sure you can do the same thing for OCS.  You don&#8217;t need to open directly in to your internal network.</p>
<p>This is not a Microsoft problem and every Internet-enabled software in the world requires some kind of port to be open which is almost always port 443 and 80.  Because you built an all-in-one box, you have no DMZ box and you&#8217;re forced to bypass the DMZ.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dietrich</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1402</link>
		<dc:creator>dietrich</dc:creator>
		<pubDate>Thu, 26 Feb 2009 15:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1402</guid>
		<description>I see.  Well, that explains your purpose.&lt;br&gt;Sorry.  I misunderstood the application.&lt;br&gt;&lt;br&gt;Color me &#039;clueless&#039;. :&#124;</description>
		<content:encoded><![CDATA[<p>I see.  Well, that explains your purpose.<br />Sorry.  I misunderstood the application.</p>
<p>Color me &#8216;clueless&#8217;. <img src='http://www.formortals.com/wp-includes/images/smilies/icon_neutral.gif' alt=':|' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jmjames</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1401</link>
		<dc:creator>jmjames</dc:creator>
		<pubDate>Thu, 26 Feb 2009 15:06:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1401</guid>
		<description>Dietrich -&lt;br&gt;&lt;br&gt;VPN is *not* the answer at all. These are services that customers and clients use, I really can&#039;t put them through the effort of configuring a VPN for a 30 minute screenshare, and most of them have IT departments that won&#039;t let it happen. In terms of the on the wire security, the Microsoft situation is good about that, because it all uses SSL anyways. The security concern is that I have untrusted users directly accessing machines within my LAN, regardless of encryption. It&#039;s like sticking a Web server or FTP server in your LAN, you&#039;d never do it.&lt;br&gt;&lt;br&gt;J.Ja</description>
		<content:encoded><![CDATA[<p>Dietrich -</p>
<p>VPN is *not* the answer at all. These are services that customers and clients use, I really can&#8217;t put them through the effort of configuring a VPN for a 30 minute screenshare, and most of them have IT departments that won&#8217;t let it happen. In terms of the on the wire security, the Microsoft situation is good about that, because it all uses SSL anyways. The security concern is that I have untrusted users directly accessing machines within my LAN, regardless of encryption. It&#8217;s like sticking a Web server or FTP server in your LAN, you&#8217;d never do it.</p>
<p>J.Ja</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Klink</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1400</link>
		<dc:creator>Marc Klink</dc:creator>
		<pubDate>Thu, 26 Feb 2009 15:03:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1400</guid>
		<description>I know some will dismiss this as offhandedly smart-assed, but really, isn&#039;t it simply because Microsoft doesn&#039;t respect you? (or any of its customers)&lt;br&gt;&lt;br&gt;I&#039;ve always found that Microsoft always works from a standpoint that, they alone, know what&#039;s best for your computer.</description>
		<content:encoded><![CDATA[<p>I know some will dismiss this as offhandedly smart-assed, but really, isn&#8217;t it simply because Microsoft doesn&#8217;t respect you? (or any of its customers)</p>
<p>I&#8217;ve always found that Microsoft always works from a standpoint that, they alone, know what&#8217;s best for your computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dietrich</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1399</link>
		<dc:creator>dietrich</dc:creator>
		<pubDate>Thu, 26 Feb 2009 12:13:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1399</guid>
		<description>VPN *is* the solution--it just requires some extra work. Every app gets its port(s) unfettered and just *one* ssl udp port is exposed to the world. ;)</description>
		<content:encoded><![CDATA[<p>VPN *is* the solution&#8211;it just requires some extra work. Every app gets its port(s) unfettered and just *one* ssl udp port is exposed to the world. <img src='http://www.formortals.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jmjames</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1398</link>
		<dc:creator>jmjames</dc:creator>
		<pubDate>Thu, 26 Feb 2009 02:43:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1398</guid>
		<description>VPN is not the solution. The whole *point* of this software is to allow people access to the service with zero install/configuration. :(&lt;br&gt;&lt;br&gt;J.Ja</description>
		<content:encoded><![CDATA[<p>VPN is not the solution. The whole *point* of this software is to allow people access to the service with zero install/configuration. <img src='http://www.formortals.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>J.Ja</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dietrich</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1397</link>
		<dc:creator>dietrich</dc:creator>
		<pubDate>Thu, 26 Feb 2009 00:26:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1397</guid>
		<description>J.Ja,&lt;br&gt;&lt;br&gt;Have you messed around with setting up OpenVPN?--a pc running Linux in the DMZ and OpenVPN server would work; or you could move it behind the Firewall because OpenVPN has no trouble with NAT Firewall issues and OpenSSL cert keys on UDP port 1194 is bullet-proof.  Set up is *easy* compared to IPSec.  Asterisk with IAX trunking over OpenVPN works fine.&lt;br&gt;&lt;br&gt;Your thoughts?  YackityYak  TalkBack!</description>
		<content:encoded><![CDATA[<p>J.Ja,</p>
<p>Have you messed around with setting up OpenVPN?&#8211;a pc running Linux in the DMZ and OpenVPN server would work; or you could move it behind the Firewall because OpenVPN has no trouble with NAT Firewall issues and OpenSSL cert keys on UDP port 1194 is bullet-proof.  Set up is *easy* compared to IPSec.  Asterisk with IAX trunking over OpenVPN works fine.</p>
<p>Your thoughts?  YackityYak  TalkBack!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jmjames</title>
		<link>http://www.formortals.com/why-does-microsoft-not-respect-my-firewall/comment-page-1/#comment-1394</link>
		<dc:creator>jmjames</dc:creator>
		<pubDate>Tue, 24 Feb 2009 14:53:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=167#comment-1394</guid>
		<description>That&#039;s what it requires... but the &quot;Communicator Web Access&quot; requires port 443 (or 80, but 443 is suggested) *directly into my LAN*. Same thing for Exchange&#039;s &quot;Outlook Anywhere&quot; functionality. This is really stupid. Sure, I pretty much trust IIS to not blow up, but that doesn&#039;t mean that the code doesn&#039;t have open bugs in it that allows it to be exploited. If someone manages to blow up the CWA system, the last thing I want/need is an exploited app in my LAN.&lt;br&gt;&lt;br&gt;J.Ja</description>
		<content:encoded><![CDATA[<p>That&#8217;s what it requires&#8230; but the &quot;Communicator Web Access&quot; requires port 443 (or 80, but 443 is suggested) *directly into my LAN*. Same thing for Exchange&#8217;s &quot;Outlook Anywhere&quot; functionality. This is really stupid. Sure, I pretty much trust IIS to not blow up, but that doesn&#8217;t mean that the code doesn&#8217;t have open bugs in it that allows it to be exploited. If someone manages to blow up the CWA system, the last thing I want/need is an exploited app in my LAN.</p>
<p>J.Ja</p>
]]></content:encoded>
	</item>
</channel>
</rss>

