Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

An actual NEW spam issue

Status
Not open for further replies.
Sep 26, 2001
61
US
Here is a new one....I think

I am using Exch 5.5 SP6

SMTP routing is enabled to my domain. Routing restrictions are set to authenticated users only.

Well....that is my problem.

We have 2 NICs. One lets mail in, and one let's it out (don't ask I didn't set it up) The spam is STILL passing (though in lower volume) because the 2nd NIC is available to spammers somehow. My telnet tests with mail-abuse.org fail on test 8 because it uses a valid hostname in the receipt (the hostname of the 2nd NIC). I can not find ANY documentation on this issue. Does anyone have any experience or ideas?? TIA
 
For example, the spam is passing through the system now in only one form: it show the "rcpt to" as

spammer@localhostXXX.mydomain.com (with my IP addy attached)

How can I stop this traffic??

TIA
 
Does that actually go through or get sent to your admin box as a failure to go through?

Is this really spam or real emails coming in to your box with return receipts on? They get fired back automatically but you can disallow them going out again as they weren't originated on your server.

Where did you get Exch 5.5 SP6 from?
 
NO. I am not getting failures. I am getting forwards from other admins who are receiving spam via our server. The header info shows that we are passing it to them, as well as the smtp tests I have run.

How can I specifically deny traffic that did not originate here? in connections on IMS?

I am sorry, I meant SP3....
 
OK. Check the IMC properties. On the routing tab, are you rerouting or not?
 
This may not be a feasable solution for you, but why don't you simply remove the second nic, or disable it, and let your firewall take care of the Network Address Translation and forward the email sent to your public IP to the Exchange server internally. That should resolve the problem.

I am assuming both nics in your Exchange server have public IP's? If so, that is a huge security risk. If not, why have two nics? If you have a good firewall you should be able to do what I describe above quite easily.

Ashley
 
Yes I am rerouting with the following restrictions:

Authenticated users and my host IP ranges...

Unfortunately Ashley, we are in a restructure project. We are replacing the firewall, as well as changing our IP scheme, so changes such as that are tough. The removal of the NIC is the best option, but I need to verify what exactly it is doing there in the first place.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top