?
Solved

Exchange Relay Authentication

Posted on 2008-10-09
8
Medium Priority
?
800 Views
Last Modified: 2013-12-04
I got an Exchange with the following situation.

Exchange 2003
ESM, under SMTP, under Access = Anonymous, basic, integrated
ESM, under SMTP, under Relay = only the list below and allow authenticated users/comps to relay
ESM, under SMTP, under Delivery, under Outbound Access = Anonymous
Smarthost SPAM Filter under SMTP, Delivery, Advanced
Telnetting to the outside, you get denied a relay
Anyone inside the network can telnet and send an email
I need emails to send both internally and externally
Users connect using Outlook cached mode, Outlook http, and webmail.

An example of my problem is UserA can telnet, and send an email from administrator@domain.com to anyone they want.  

I want to stop this, but don't want to stop mail flow or screw up the smart host?  To do this, would I just change the outbound authentication to basic/integrated?  Would that also entail setting it to authenticate with the smarthost?

Thanks,
0
Comment
Question by:deadite
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
8 Comments
 
LVL 33

Expert Comment

by:Exchange_Geek
ID: 22685239
"An example of my problem is UserA can telnet, and send an email from administrator@domain.com to anyone they want."

This basically you are open to relay.

Since, if you are using telnet to connecting to your local Exchange server - and when you try to perform mail from: administrator@domain.com (this does not matter)
rcpt to: administrator@outsidedomain.com (when you hit enter - you should get a messages - unable to relay"

If you are trying to telnet to some one else Exchange server and you drop an email using your administrator account - you cannot help it.
0
 
LVL 13

Accepted Solution

by:
ach_patil earned 1000 total points
ID: 22685463
To stop anyone internal telnetting and sending an email. Do the following
Go to the the Relay Tab under the SMTP Virtual Server.
There is little Tick Box which says "Allow all computers which successfully suthenticate to relay, regardless of the list above". Just untick it.
Once this is done internal users will not be able to relay using your Exchange Server.

I am not very clear about your external user Relay issue.
0
 
LVL 33

Expert Comment

by:Exchange_Geek
ID: 22685620
He only has

"ESM, under SMTP, under Relay = only the list below and allow authenticated users/comps to relay"

where did that check box come into the picture - he does not have that checked bro.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 8

Author Comment

by:deadite
ID: 22686346
Exchange_Geek:
Internal users cannot relay to outside networks, and outside networks cannot relay into me.  The relay is strictly internal.

ach_patil:
If I uncheck that box, wouldn't that interrupt my mail flow and pretty much eliminate any authentication?  

Exchange_Geek:
Sorry about the confusion, I wrote that in short hand.  There is a radio button select that says Only let the list below, then there is a check box that says Allow authenticated users and computers to relay regardless of the list
0
 
LVL 13

Expert Comment

by:ach_patil
ID: 22686487
No, it wont interrupt your mail flow. That box is just to prevent Authenticated users trying to relay using your Exchange Server.

If you have any applications that send out messages. Add their IP Addresses in the Allowed List of servers

I have used it my network to stop unnecessary internal relay and work fine.
0
 
LVL 8

Author Comment

by:deadite
ID: 22686658
What about the anonymous authentication under the virtual SMTP connector as well as the outbound one?  Do either of those need changed?  

I should be able to test this later tonight, but just want to get it done quickly and without interrupting mail flow.
0
 
LVL 33

Expert Comment

by:Exchange_Geek
ID: 22686762
http://www.comptechdoc.org/os/windows/exchange/exchsmtpvs.html

Check this link for basic settings for SMTP VS - there is a connection tab which has an IP address specified in the link - this isn't required.
0
 
LVL 8

Author Comment

by:deadite
ID: 22706474
The above default settings are on 2000 Exchange, they are slightly different in 2003....  None the less, I got my answer
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
New style of hardware planning for Microsoft Exchange server.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses
Course of the Month13 days, 4 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question