I only have one public IP. Do I block port 25 at the Pix?
Thanks.
Main Topics
Browse All TopicsI am having a problem getting repeatedly listed on the CBL for Spam. I have checked for viruses and spyware and keep coming back clean. I also have a St. Bernard E-prism M1000 that filters all email traffic. I am running Exchange 2003. I have checked my email reports on the M1000 and I do not see anything that indicates a spam problem. I have recently updated my e-prism from the m500 to the M1000 and this is when the problem started, but I can not find any configuration settings that could be causing a problem. Does anybody have any suggestions?
Thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
You can get on the CBL due to backscatter. This is where a spammer forges a senders email address and sends it to a non existant user on your system. If your exchange server or the spam filtering server is not checking to see if the recipient is valid before it accepts the mail then you will be sending out non delivery reports to the forged senders email address.
Exchange 2003 can do it. However it is only effective if Exchange is the primary receiver of the email. You have indicated that you are using an appliance, so the appliance needs to do it. Look for LDAP or recipient filtering in that device.
For the PIX you need to configure a rule that blocks all traffic on port 25 except for the Exchange server and the appliance, or use an SMTP connector to route outbound email out through the appliance.
Simon.
I think I discovered my problem. I noticed today that I had a secondary entry in my reverse dns MX record. The particular ip was for an open relay mail server with in ATT's network. I noticed yesterday when running reports on my eprism that this server was sending me a lot of mail and it was all spam. I have requested that ATT remove this entry from my MX record and hopefully this solves the problem.
Thanks for the help and I will let you know in about 24 hours if that solves my problem.
Business Accounts
Answer for Membership
by: SembeePosted on 2007-09-12 at 12:55:50ID: 19879408
Do you have multiple external IP addresses?
Have you blocked any machines from inside from being able to send email out to the internet? Block port 25 outbound.
The most common cause is a compromised machine inside the network sending messages.
Simon.