Exchange Server - Exchange 2007 ans antispam rules

Asked By Fabrice on 01-May-10 02:55 AM
Hello,

I have just migrated from Exchange 2003 to 2007 sp2.
I have also a smarthost in DMZ. Not a edge serveur.

With Exch2003 I used IMF with my own SCL. It works fine and many spam were
stopped.


I have "installed" the antispam rules under Exch2007 and configured it with
the same SCL rules. But now no emails are stopped.
When I look in an email header I can note the following informations :

X-MS-EXCHANGE-ORGANISATION-Antispam-report : IPONALLOWLIST
and
X-MS-EXCHANGE-ORGANISATION-SCL:-1

My smarthost is not in Green list, but just authorized on the reception
connector.

Why all the emails from Internet are indicated with "IPONALLOWLIST" and so
no controlled by antispam rules ?

thanks for your help.
fabrice









Bonjour ? tous

Je viens de passer d'Exchange 2003 ? Exchange 2007.
J'utilise un smarthost en DMZ.

Sous la version 2003, j'utilisais pleinement IMF avec des SCL personnalis?s.
Cela fontionnait tr?s bien et beaucoup de courriers de spam ?taient
supprim?s.

Sous 2007, j'ai activer ?galement les r?gles antispam avec les m?mes SCL.
Mais d?sormais plus aucun email ne semble r?ellement trait? par l'antispam
exchange 2007. Je me suis aper?u que le hearder des emails contenait tous
la mention d'IPONALLOWLIST et donc avec un scl de -1
(X-MS-EXCHANGE-ORGANISATION-SCL:-1).

Cela voudrait dire que l'adresse de mon smarthost se trouve dans la liste
verte ce qui n'est pas le cas. Ce dernier est juste autoris? sur le
connecteur de r?ception. normal.

Si vous aviez une id?e.
Merci par avance.

fabrice


Rich Matheisen [MVP] replied to Fabrice on 01-May-10 02:11 PM
What boxes are checked on the "Authentication" tab of the connector?
If you have checked "Externally secured" that allows the inbound e-mail
on that connector to bypass all spam filters.
---
Rich Matheisen
MCSE+I, Exchange MVP
Fabrice replied to Rich Matheisen [MVP] on 02-May-10 03:28 AM
Hello

Those are the boxes checked on my sender connector :

- Tls (transport layer security)
- Basic authentication
- Exchange Server authentication
- Integrated authentication


Thanks for your help

fabrice
Rich Matheisen [MVP] replied to Fabrice on 02-May-10 12:14 PM
[ snip ]


So, if you use the get-ipallowlistentry cmdlet the IP address in
question is not found?

Get-IPAllowListentry -ipaddress 1.2.3.4

Do you have any IP Allow List Providers?
get-IPAllowListProvider

Is the IP address listed on one of them?
test-IPAllowListProvider
---
Rich Matheisen
MCSE+I, Exchange MVP