Solved

Remove VPN users - Mail blocked by IML / SCL

Posted on 2008-10-24
7
648 Views
Last Modified: 2013-11-16
I have set up a remote VPN solution for a client (Cisco ASA running WebVPN) all appears to be fine, however remote users who are emailing other users in the same mail domain. are getting their mail blocked by the Exchange 2003 Intelligent Mail filter.

_______
example header from a filtered email (X-SCL rating of 8) from home worker to office worker:
 
x-sender: usera@domainname.org.uk
x-receiver: userb@domainname.org.uk
X-SCL: 8 91.28%

Now I know you can't "whitelist" against the IMF, but you are supposed to be able to bypass it by IP address, so Ive added the IP address of the firewall applieance, and the subnet thats being leased to the remote VPN users. (And enabled this on the Default SMTP virtual Server)

Still the problem remains?

Has anyone Cisco expert or Exchange Expert seen this before? Im loathed to log a call to Cisco TAC because they will blame Exchange and Im loather to call Microsoft for the same reason

Any thoughts?

0
Comment
Question by:Pete Long
  • 4
  • 3
7 Comments
 
LVL 12

Accepted Solution

by:
florin_s earned 500 total points
Comment Utility
Hi,

We do not use the IMF in our company but I might have found something that helps, it seems that there are some bugs related to the IMF:

Therefore, if you need messages with the SCL level of 8 to be blocked, and messaged with the SCL level of 6 to be moved to the user's Junk E-Mail folder, you will need to configure the threshold levels with 7 and 5 respectively:

Please see the following link:

http://www.petri.co.il/bug_in_imf_interface.htm
0
 
LVL 57

Author Comment

by:Pete Long
Comment Utility
I had a read through that, which sent me round the houses to http://support.microsoft.com/default.aspx?scid=kb;en-us;867633 which tells me these guys should get stamped with an SCL of -1 anyway? The article above is more concerned with the wrong levels getting blocked, these guys should not get a high SCL rating at all - its essentially internal mail flow? - still head scrathing :(

Thanks for your input m8
0
 
LVL 12

Assisted Solution

by:florin_s
florin_s earned 500 total points
Comment Utility
As I said before I also have no real experience with IMF but as I see this might be a trial and error situation, try with different raitings.
I am curious about the result, anyway I will ask my colleagues if they encountered this before and post here.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 57

Author Comment

by:Pete Long
Comment Utility
Call opened to Cisco TAC
0
 
LVL 57

Author Comment

by:Pete Long
Comment Utility
Still with TAC.........................
0
 
LVL 12

Expert Comment

by:florin_s
Comment Utility
Do you have something until now, because until now I think it takes a bit long.
What did they tell you?
0
 
LVL 57

Author Comment

by:Pete Long
Comment Utility
waiting on third party to send info to CIsco :(
0

Featured Post

Why spend so long doing email signature updates?

Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

Join & Write a Comment

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now