Jump to content

Recommended Posts

Posted

Hi,

 

I'm setting up O365 up in a hybrid configuration with our on-site Exchange 2010 server. Initially we just want incoming mail to flow through EOP to give us extra protection against malware etc. Eventually (and at our own pace) we will migrate all our mailboxes to the cloud and retire our Exchange server.

 

To get to the next phase, I need to supply our ISP with a list of port numbers and IP addresses so that they can configure their firewall to allow the correct traffic to flow in/out. They charge £147 to do this. They have made it very clear that if any further changes need to be made, they will charge us another £147!

 

A Microsoft engineer pointed me here : https://support.office.com/en-us/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2?ui=en-US&rs=en-US&ad=US#BKMK_EOP

 

Which I find a bit of an overload. Has anyone done this recently who could advise? I don't want to have my ISP stinging me for multiple payments of £147!

  • 3 weeks later...
Posted
Good luck with the the IP ranges. We tried it and MS change them so frequently you'll be forever playing catch-up. We often found similar-but-different ranges being blocked and checking them out all were owned by MS so I'm not convinced about that web page being accurate at any given time.
Posted
Good luck with the the IP ranges. We tried it and MS change them so frequently you'll be forever playing catch-up. We often found similar-but-different ranges being blocked and checking them out all were owned by MS so I'm not convinced about that web page being accurate at any given time.

 

This is what's worrying me, especially as our ISP will charge us £147 for ANY change request!

 

What our ISP is now suggesting is that they:

 

Permit internally initiated traffic from IP of exchange server to any IP on ports 53 (TCP and UDP) and 25, 587, 143, 993 (all TCP)

Permit Externally initiated traffic from any IP to IP of exchange server on ports 53 (TCP and UDP) and 25, 587, 143, 993, 80 and 443 (all TCP)

 

Which will allow (almost) anything to come through to our Exchange server and then we do the IP restricting at our end (with a HUB receive connector?) - I've just taken a look and the O365 Hybrid config wizard actually creates an O365 connector with IP addresses so ... maybe that's one less thing to think about?!

 

Our ISP is also saying that we may encounter proxy server issues (not sure if we will the Hybrid config wizard completed without issue and I've synced all users with AD, the only thing that could fall over now is mailbox migration?) & if they have to tweak our proxy server, they will be charging us again.

 

Eek.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...