Sie sind auf Seite 1von 28

Module 10: Configuring

Internet Protocols
Overview

 IIS and Exchange 2000 Integration


 Examining Client Connectivity and
Security
 Examining Kerberos Authentication
 Front-end/Back-end Server
Configuration and Security
 Configuring NNTP Services
 Troubleshooting Client Connectivity by
Using Telnet
IIS Integration with Exchange 2000

 Default Protocols Supported by IIS


 Protocols Supported by IIS with
Exchange 2000
 Virtual Server Functionality in
Exchange 2000
Default Protocols Supported by IIS

Windows 2000

IIS NNTP HTTP SMTP


Protocols Supported by IIS with
Exchange 2000

Exchange 2000

IIS NNTP HTTP SMTP POP3 IMAP4


Virtual Server Functionality in
Exchange 2000

Exchange 2000
Server

IMAP4
Virtual IMAP4 Client
Server

POP3
Virtual
Server

POP3 Client
Examining Client Connectivity and
Security

 IMAP4 and POP3 Client Capabilities


 POP3 Message Transfer
 IMAP Message Transfer
 POP3 and IMAP4 Authentication and
Encryption
 LDAP Functionality
IMAP4 and POP3 Client Capabilities
Exchange 2000
Server

Virtual
Server
NNTP

Virtual
Server
POP3

Virtual
Server
IMAP4
POP3 Message Transfer

Established Connection (110)


Greeting
Command(s) Listening
Port 110
Response(s)

Quit
POP3 Server
Client Signing Off
IMAP4 Message Transfer

Established Connection (143)


Greeting
Command(s) Listening
Port 143
Response(s)

Logout
IMAP4 Server
Client Signing Off
POP3 and IMAP4 Authentication and
Encryption

TCP/IP
PORT
POP3 110
POP3-SSL 995
Basic or Windows Integrated Authentication

IMAP4 1
Basic or Windows Integrated Authentication using SSLIMAP4-SSL 4
3
9
POP3 or POP3 or
9
IMAP4 Server IMAP4 Server
3
LDAP Functionality

Domain
P 389 Controller
LDA

DSACCESS
LD Windows 2000
AP
326
System
Recipient Update 8
Service
Attendant
LDA
P 32
68
Exchange 2000
Global Catalog
Server

Windows 2000
Kerberos Authentication
Windows 2000 DC
Kerberos Key Distribution Center
ClientRequest a ticket for Ticket-Granting Service
1
Authentication
Return Ticket-Granting Ticket to client
2 Service
Send Ticket-Granting Ticket and
request for ticket to Application Server
3
Ticket-Granting
Return ticket for the Application Server
4 Service

5 session ticket to Application Server


Send

(Optional) Send
confirmation of
identity to client
Application Server
Front-end/Back-end Server
Configuration and Security

 Introduction to Front-End/Back-End
Servers
 Scalability and Load Balancing
 Authentication Process
 Front-end Server Sits Within the
Perimeter Network
 Front-end Server Sits Outside the
Firewall
 Front-end Server Sits Inside the
Firewall
 Alternatives to Opening TCP Ports
Introduction to Front-end/Back-end
Servers
Exchange 2000
Back-end Servers

Mail1

POP3

Mail2
POP3 Exchange 2000
Client Front-end Server
LDAP
Mail3

Mail4
Active Directory-based
Domain Controller
Scalability and Load Balancing

DNS mail.nwtraders.msft
192.168.1.1
192.168.1.2
PO
POP3 P3
Client

Front-end
Servers PO
P3

Back-end
Servers
Authentication Process

Front-end Server Receives User’s Log On Request

ont-end Server Queries Active Directory for User’s Mailbox

Front-end Server Sends Request to the Correct Back-end S

Back-end Server Authenticates the User


Back-end Server Sends Results to the Front-
end Server
Front-end Server Sends Results to the Client
Front-end Server Sits Within the
Perimeter Network

You need to pass POP3 Global Catalog


Server

Firewall 1 Firewall 2

POP3 Front-end Back-end


Client Exchange Server Exchange Servers

You need to pass POP3, NetBIOS,


Perimeter RPC, Kerberos and LDAP
Network
Front-end Server Sits Outside the
Firewall
Global Catalog
Server

POP3 Front-end Back-end


Client Exchange Server Exchange Servers

You need to pass POP3, NetBIOS,


RPC, Kerberos and LDAP
Front-end Server Sits Inside the
Firewall
Global Catalog
Server

You need to pass POP3

POP3 Front-end Back-end


Client Exchange Server Exchange Servers
Alternatives to Opening Ports

 Open DNS and RPC Ports Between the


Perimeter Network and the Intranet
by:
 Creating DNS hosts files on each of the
front-end servers in the perimeter
network
 Editing the registry of each front-end
server to specify the name of the
domain controller and global catalog
server
Configuring NNTP Services

 Configuring NNTP Virtual Servers


 Creating and Storing Newsgroups
 Creating Newsfeeds
Configuring NNTP Virtual Servers

Pull
Servers

Exchange 2000
Server

5 000
NNTP >
P 119
Virtual TC 563
Server SSL
Creating and Storing Newsgroups

Pull
Servers

Exchange 2000
Server Newsgroups
Finance
NNTP Documents
Virtual Resumes
Server

Public File File Share


Folders System \\Server\Share

Finance Documents Resumes


Creating Newsfeeds
USENET Host

Push
Feed

News
Feed

NNTP Clients NNTP Subordinate NNTP Master


Servers Server
Troubleshooting Client Connectivity
By Using Telnet

1 Established Connection (110)


Greeting
2 USER Exchange2000alias
Response(s)
Listening
3 Port 110
PASS password

Response(s)
Client Server
4 LIST
Lab A: Creating and Configuring an
IMAP4 Virtual Server
Review

 IIS and Exchange 2000 Integration


 Examining Client Connectivity and
Security
 Examining Kerberos Authentication
 Front-end/Back-end Server
Configuration and Security
 Configuring NNTP Services
 Troubleshooting Client Connectivity by
Using Telnet

Das könnte Ihnen auch gefallen