Solved

Exchange 2003 Open Relay Cannot be Shutdown

Posted on 2004-04-12
4
546 Views
Last Modified: 2010-03-05
OK, confirmed the following from http://support.microsoft.com/?id=324958:

Right-click Default SMTP Virtual Server and then click Properties.
Click the Access tab.
Click the Relay... button at the bottom.
The default settings block open relay. The default settings are as follows:
Select Only the list below.
The Computers dialog box shows Access Granted to the Internal IP address of the Small Business Server network and to the external IP address (if the server has more than one network card.)
Make sure that Allow all computers which successfully authenticate to relay, regardless of the list above is selected.
Set the Default SMTP Virtual Server configuration for relaying as indicated, which restores its settings to their defaults.

Testing by connecting on port 25 and sending mail to a outside domain from an outside domain works fine. However, my understanding of the above would lead me to believe that should not be possible. While doing this simple test, 12,000 SPAM messages are in my queue, although all messages are going to a non-existant smart host.

If i re-install SMTP, the telnet test shows that open relay is closed, adn the settings above are the same. But, of course Exchange doesn't work. As soon as i re-install Exchange 2003, the open relay is off and running again.

This is of course a major issue, and every time i find an article on how to close it, it is already closed, but as soon as SMTP is started it's wide open again. Anyone have any ideas at all?
0
Comment
Question by:maladyetz
  • 2
  • 2
4 Comments
 
LVL 2

Accepted Solution

by:
spakko earned 500 total points
ID: 10809364
Hmmm, I do not agree with this article. Try this:

1. Open SMTP properties.
2. Go to the Access tab.
3. UNTICK allow authenticaed users to relay! (there is an exploit that uses this to relay)
4. In the computers dialogue box make sure your subnet is listed (ie a group of computers in Exhange terminology), eg 192.168.0.0

Try that, it should work.
0
 

Author Comment

by:maladyetz
ID: 10809390
OK, trying this, unfortunately there could be over 10K in the queue, if it stops growing and i cna clean it out, that would be a sign this is working. i did try the telnet test and was rejected, so hopefully this will resolve it. Let you know tomorrow most likely.
0
 

Author Comment

by:maladyetz
ID: 10814409
This worked, and should be noted somewhere on Microsoft's site as an issue. Thank you so much. It is working like a charm, now that the 30K emails are deleted.
0
 
LVL 2

Expert Comment

by:spakko
ID: 10818499
Most welcome :)
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
In-place Upgrading Dirsync to Azure AD Connect
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question