Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Remove VPN users - Mail blocked by IML / SCL

Posted on 2008-10-24
7
Medium Priority
?
673 Views
Last Modified: 2013-11-16
I have set up a remote VPN solution for a client (Cisco ASA running WebVPN) all appears to be fine, however remote users who are emailing other users in the same mail domain. are getting their mail blocked by the Exchange 2003 Intelligent Mail filter.

_______
example header from a filtered email (X-SCL rating of 8) from home worker to office worker:
 
x-sender: usera@domainname.org.uk
x-receiver: userb@domainname.org.uk
X-SCL: 8 91.28%

Now I know you can't "whitelist" against the IMF, but you are supposed to be able to bypass it by IP address, so Ive added the IP address of the firewall applieance, and the subnet thats being leased to the remote VPN users. (And enabled this on the Default SMTP virtual Server)

Still the problem remains?

Has anyone Cisco expert or Exchange Expert seen this before? Im loathed to log a call to Cisco TAC because they will blame Exchange and Im loather to call Microsoft for the same reason

Any thoughts?

0
Comment
Question by:Pete Long
  • 4
  • 3
7 Comments
 
LVL 12

Accepted Solution

by:
florin_s earned 2000 total points
ID: 22794846
Hi,

We do not use the IMF in our company but I might have found something that helps, it seems that there are some bugs related to the IMF:

Therefore, if you need messages with the SCL level of 8 to be blocked, and messaged with the SCL level of 6 to be moved to the user's Junk E-Mail folder, you will need to configure the threshold levels with 7 and 5 respectively:

Please see the following link:

http://www.petri.co.il/bug_in_imf_interface.htm
0
 
LVL 57

Author Comment

by:Pete Long
ID: 22794895
I had a read through that, which sent me round the houses to http://support.microsoft.com/default.aspx?scid=kb;en-us;867633 which tells me these guys should get stamped with an SCL of -1 anyway? The article above is more concerned with the wrong levels getting blocked, these guys should not get a high SCL rating at all - its essentially internal mail flow? - still head scrathing :(

Thanks for your input m8
0
 
LVL 12

Assisted Solution

by:florin_s
florin_s earned 2000 total points
ID: 22798782
As I said before I also have no real experience with IMF but as I see this might be a trial and error situation, try with different raitings.
I am curious about the result, anyway I will ask my colleagues if they encountered this before and post here.
0
WatchGuard Case Study: Museum of Flight

“With limited money and limited staffing, we didn’t have a lot of choices in terms of what we could do to bring efficiency. WatchGuard played a central part in changing that.” To provide strong, secure Wi-Fi access within the museum, Hunter chose to deploy WatchGuard’s AP120 APs.

 
LVL 57

Author Comment

by:Pete Long
ID: 22812228
Call opened to Cisco TAC
0
 
LVL 57

Author Comment

by:Pete Long
ID: 22921625
Still with TAC.........................
0
 
LVL 12

Expert Comment

by:florin_s
ID: 22922089
Do you have something until now, because until now I think it takes a bit long.
What did they tell you?
0
 
LVL 57

Author Comment

by:Pete Long
ID: 22922509
waiting on third party to send info to CIsco :(
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
How to effectively resolve the number one email related issue received by helpdesks.
how to add IIS SMTP to handle application/Scanner relays into office 365.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Suggested Courses
Course of the Month12 days, 10 hours left to enroll

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question