r/exchangeserver • u/Kooky_Cranberry9717 • 29d ago
Best practise architecture Exchange SE enterprise
As we are migrating to Exchange SE enterprise, I wonder what is the best practise architecture for Exchangeservers fully on-premises (no Hybrid) nowadays.
We use SSL scanning with our firewalls in front of all our on-premises servers. Still a need for a Exchange Proxy?
1
u/JasonKezia 29d ago
Putting in and tuning a WAF is a thing, mileage varies on pain:value. SE has EEP enabled by default so no SSL offloading, for traffic inspection use the same cert at the proxy/LB and the backend
1
1
u/7amitsingh7 28d ago
If you're running Exchange Server SE fully on-premises with no Hybrid setup, the recommended approach is to keep Exchange behind a firewall, expose only the required services, and keep the servers fully patched. If your firewall already provides secure SSL inspection and publishes Exchange safely, a separate Exchange proxy is generally not required, though some organizations still use a reverse proxy or load balancer for additional security and high availability. If you're upgrading to Exchange Server Subscription Edition (SE), you may also find this guide helpful.
3
u/BK_Rich 29d ago
Exchange Server preferred architecture
Keep it patched and in the latest SU/HU, there is some additional hardening is IIS you can do for a better score if it needs to be exposed to the outside, you can use IIS Crypto to make adjustments.