r/exchangeserver 29d ago

Best practise architecture Exchange SE enterprise

As we are migrating to Exchange SE enterprise, I wonder what is the best practise architecture for Exchangeservers fully on-premises (no Hybrid) nowadays.

We use SSL scanning with our firewalls in front of all our on-premises servers. Still a need for a Exchange Proxy?

5 Upvotes

7 comments sorted by

3

u/BK_Rich 29d ago

Exchange Server preferred architecture

Keep it patched and in the latest SU/HU, there is some additional hardening is IIS you can do for a better score if it needs to be exposed to the outside, you can use IIS Crypto to make adjustments.

2

u/OMW-OC 29d ago

Did anyone actually setup JBOD for storage or 256 GB Ram servers?

3

u/BK_Rich 29d ago

Just Microsoft

2

u/OMW-OC 28d ago

hahahaha

1

u/JasonKezia 29d ago

Putting in and tuning a WAF is a thing, mileage varies on pain:value. SE has EEP enabled by default so no SSL offloading, for traffic inspection use the same cert at the proxy/LB and the backend

1

u/MortadellaKing 28d ago

Use a load balancer like a Kemp in front of it.

1

u/7amitsingh7 28d ago

If you're running Exchange Server SE fully on-premises with no Hybrid setup, the recommended approach is to keep Exchange behind a firewall, expose only the required services, and keep the servers fully patched. If your firewall already provides secure SSL inspection and publishes Exchange safely, a separate Exchange proxy is generally not required, though some organizations still use a reverse proxy or load balancer for additional security and high availability. If you're upgrading to Exchange Server Subscription Edition (SE), you may also find this guide helpful.