Re: Setup inbound mail filter?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Thanks for your help! I hope this will eliminate the virus problem we've had
lately.

"Bharat Sonja" wrote:

No inherent risks as such, I just pointed out a best practice but what you
have now will work.
--
Bharat Suneja
MCSE, MCT
www.zenprise.com
blog: www.suneja.com/blog
-----------------------------------------


"Courtney R" <CourtneyR@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F6A5C045-B023-48AA-B7F9-7CE6AAC1E971@xxxxxxxxxxxxxxxx
If we use the present SMTP Virtual server, adding the FrontBridge address
and
do not setup a new SMTP Virtual Server/Connector...is there a inherent
security risk? Will it not work? I only ask, as setting up a new SMTP
Virtual Server/Connector is asking a bit much in the time we have allowed.
And I don't want to do too many chages at once to our exchange setup.

Also, our firewall is rather old, so we cannot sepcify frontbridge ip's on
the firewall.

Thanks!

"Bharat Suneja" wrote:

Restart SMTP virtual server. Yes, only on the box with outside connection
(inbound SMTP is open to that box on firewall).

Ideally the box that's exposed to the internet (but needs to talk to
internal Exchange server as well) should have two SMTP Virtual Servers.
Leave the default to talk to the other Exchange server. Enable
Windows-integrated auth on this, can remove anonymous.

Setup a SMTP Connector for address space * and use the second/additional
SMTP virtual server, only enable anonymous authentication on the SMTP vs.
On
your firewall, open inbound SMTP from Frontbridge IPs only to the
public/NATted IP address of this SMTP vs. Do the same on the SMTP vs
properties | Access tab.
--
Bharat Suneja
MCSE, MCT
www.zenprise.com
blog: www.suneja.com/blog
-----------------------------------------


"Courtney R" <CourtneyR@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:20EE8DA7-F5A3-4530-ADA3-0D3B0C8913D9@xxxxxxxxxxxxxxxx
We have two Exchange 2000 servers. One handles all of the inbound
traffic
from outside beyond the firewall, and the other server is just for
internal
e-mail, etc. We have Frontbridge e-mail filtering service. Recently a
large
# of virus and Spam has been getting in. What we will do is specify to
accept inbound mail traffic from only Frontbridge servers.

I have never done this, but I'm assuming I need to input these IP
addresses
in the Default SMTP Virtual Server>Access>Connection
Control>Connection-
Select 'Only from the List Below' and enter in the Frontbridge IP
addresses?
And do I need to restart Exchange or IIS services?

Do I only have to do this on the server that has the outside
connection?
What about our main exchange server on our network, behind the
firewall?
Do
I have to add the IP's on that SMTP Virtual Server? Do they replicate
to
the
main Exchange server?

Thanks







.



Relevant Pages

  • Re: [opensuse] dictionary attacks
    ... limit of the magic number of E-Mails, she couldn't connect to the SMTP ... server for 24 hours. ... SSHd is probably the wrong criteria, but detecting the IP of an incoming ... turning off that IP at the firewall could be effective. ...
    (SuSE)
  • RE: Could not access CDO.Message object
    ... anti-virus/Anti-spam applications or firewall to test the issue. ... Please perform a clean boot on the server box to see if it helps. ... Does it use its own SMTP ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Completely replace software firewall with hardware firewall?
    ... Sygate Personal Firewall. ... I've found that my ISP provided SMTP server has been ... firewall and hardware router/firewall independently to verify this). ...
    (comp.security.firewalls)
  • Re: Completely replace software firewall with hardware firewall?
    ... Sygate Personal Firewall. ... I've found that my ISP provided SMTP server has been ... firewall and hardware router/firewall independently to verify this). ...
    (alt.computer.security)
  • Re: Setup inbound mail filter?
    ... as setting up a new SMTP ... Also, our firewall is rather old, so we cannot sepcify frontbridge ip's on ... Leave the default to talk to the other Exchange server. ...
    (microsoft.public.exchange.admin)