You should install Wireshark on the network's internet gateway (hopefully a Linux box) and then you should be able to see all traffic coming from or going to the internet... if you cannot install wireshark on the network's internet gateway (because it's a router or your client does not want you to install anything intç there, or any other reason) you could make a tap by connecting a small network hub (not a switch, unless it's capable of replicating all traffic on one port) between the gateway and the net, and then plugging a computer with wireshark in that hub
a "port 25" command in the capture filter will help you to not analyze all traffic but only smtp
legal outgoing smtp traffic should only originate from your exchange server, and not from any other machine in the net..
Main Topics
Browse All Topics





by: perkins328Posted on 2008-04-26 at 19:14:49ID: 21447782
Sounds like if you think a Machine sending spam, I would look for BOTS running very popular, If the client has a Firewall, Limit the mailserver only the ability to send from port 25. Log the firewall traffic, this will also help. Monitor the Queue in Exchange to see what mail is being Queued