How to Cheat at Configuring Exchange Server 2007: Including Outlook Web, Mobile, and Voice Access

Remember that the Edge Transport server role should be isolated in the perimeter network (also called a DMZ or screened subnet), away from your Active Directory. The server role should therefore be installed in a workgroup on a standalone server.
It s highly recommend that you install two network adapters in the server on which you re planning to install the Edge Transport server. One network adapter should be Internet facing; the other should be intranet facing. This way you can secure the Send and Receive connectors much more efficiently than would be the case with only a single network adapter.
If your organization consists of multiple forests and you want to use the EdgeSync service in each of them, you must replicate all recipient addresses to one forest and then set up an edge subscription to that forest, because the EdgeSync service supports replication with only one forest at a time.
Bear in mind that to use several of the antispam features, you must use an edge subscription. This way, configuration as well as recipient data are replicated from Active Directory to the ADAM store using the EdgeSync service. It is possible to not use an EdgeSync subscription, but you will then not be able to use several of the antispam features on the Edge Transport server. In addition, you need to...