I'm a bit anal about putting Windows machines in the DMZ. I have an exchange server that I would like to be completely behind the firewall (local IP only). I will be using the SMTP Proxy (for blacklist and antivirus) to process mail.
I was thinking of configuring the SMTP proxy as you normally would with transparent mode turned off and then configuring DNAT rules for other protocols as needed. I would like to keep the existing public address that my exchange server is using. Would I add this as an additional IP to the public interface?
Does this sound like a good idea? Is there a better way to accomplish this? Are there any know issues with this sort of configuration?
Thanks in advance for your help!
This thread was automatically locked due to age.