Configuring Edge Transport Server: Recommended Ports and Filtering Security
Setting up an Edge Transport Server is an essential step in securing your Microsoft Exchange Server. The Edge Transport Server is a specialized server role that is placed in the Demilitarized Zone (DMZ) or outside the Local Area Network (LAN) to provide additional security for the Exchange Server. This article will discuss the recommended ports and filtering security for configuring the Edge Transport Server.
Recommended Ports for Edge Transport Server
The Edge Transport Server listens on specific ports for incoming and outgoing mail flow. The following ports are recommended for the Edge Transport Server:
- SMTP (Simple Mail Transfer Protocol): The default SMTP port is 25. This port is used for mail flow between mail servers. It is recommended to use Transport Layer Security (TLS) encryption on this port to secure the mail flow.
- SMTP Submission: The default SMTP submission port is 587. This port is used for mail submission by mail clients. It is recommended to use TLS encryption on this port as well.
- SMTP over TLS (STARTTLS): The default SMTP over TLS port is 587. This port is used for mail flow between mail servers that support TLS encryption.
Filtering Security for Edge Transport Server
Filtering security is an essential feature of the Edge Transport Server. It helps to protect the Exchange Server from spam, viruses, and other malicious traffic. The following are the recommended filtering security configurations for the Edge Transport Server:
- Connection Filtering: Connection filtering helps to block connections from known malicious IP addresses. The Edge Transport Server can be configured to use Microsoft's connection filtering service or a third-party service.
- Recipient Filtering: Recipient filtering helps to block messages that are sent to non-existent recipients. The Edge Transport Server can be configured to reject messages addressed to non-existent recipients.
- Sender Filtering: Sender filtering helps to block messages from known spam senders. The Edge Transport Server can be configured to reject messages from known spam senders.
- Content Filtering: Content filtering helps to block messages that contain malicious content. The Edge Transport Server can be configured to scan messages for viruses, malware, and other malicious content.
Configuring Filtering Security
Configuring filtering security on the Edge Transport Server is a straightforward process. The following steps can be used to configure filtering security:
- Open the Exchange Management Console (EMC) and navigate to the Edge Transport Server.
- Click on the "Edge Transport" node and select "Filtering Configuration".
- Configure the connection filtering, recipient filtering, sender filtering, and content filtering settings as required.
- Click "OK" to save the changes.
Configuring the Edge Transport Server with recommended ports and filtering security is an essential step in securing your Microsoft Exchange Server. The recommended ports for the Edge Transport Server are SMTP (25), SMTP Submission (587), and SMTP over TLS (587). Filtering security features such as connection filtering, recipient filtering, sender filtering, and content filtering can be configured to protect the Exchange Server from spam, viruses, and other malicious traffic.