[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Did I Close Open Relay Properly on Exchange SBS 2003 R2

Posted on 2008-11-05
1
Medium Priority
?
551 Views
Last Modified: 2013-11-30
my public static ip got blacklisted.  i checked my exchange sbs 2003 r2 server for open relay and turned on logging.  I noticed that a lot of other public ip's were doing open relay.  I turned some settings to turn open relay off and was wondering if the enclosed log shows that outside public ip's are no longer able to open relay via my server.  I included quite a few lines of the log above and below the time when i turned the open relay settings off.  thanks!
19:18:31 200.118.89.137 EHLO - 250
19:18:31 200.118.89.137 MAIL - 250
19:18:37 200.118.89.137 RCPT - 550
19:18:37 200.118.89.137 QUIT - 240
19:20:21 216.161.141.12 - - 0
19:21:08 67.219.102.102 HELO - 250
19:21:08 67.219.102.102 MAIL - 250
19:21:08 67.219.102.102 RCPT - 250
19:21:09 67.219.102.102 DATA - 250
19:21:09 66.196.97.250 - - 0
19:21:09 67.219.102.102 QUIT - 240
19:22:18 62.43.67.157 HELO - 250
19:22:18 62.43.67.157 MAIL - 250
19:22:18 62.43.67.157 RCPT - 250
19:22:21 62.43.67.157 DATA - 250
19:22:21 62.43.67.157 QUIT - 240
19:22:36 83.24.23.188 HELO - 250
19:22:36 83.24.23.188 MAIL - 250
19:22:37 83.24.23.188 RCPT - 250
19:22:37 65.254.254.51 - - 0
19:22:40 83.24.23.188 DATA - 250
19:22:40 83.24.23.188 QUIT - 240
19:23:25 89.34.104.35 EHLO - 250
19:23:26 89.34.104.35 MAIL - 250
19:23:26 89.34.104.35 RCPT - 250
19:23:27 89.34.104.35 DATA - 250
19:23:27 89.34.104.35 QUIT - 240
19:26:05 216.39.127.87 EHLO - 250
19:26:05 216.39.127.87 MAIL - 250
19:26:05 216.39.127.87 RCPT - 250
19:26:05 216.39.127.87 DATA - 250
19:26:05 216.39.127.87 QUIT - 240
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2008-11-04 19:29:19
#Fields: time c-ip cs-method cs-uri-stem sc-status 
19:29:19 79.125.244.92 EHLO - 250
19:29:20 79.125.244.92 MAIL - 250
19:29:20 79.125.244.92 RCPT - 250
19:29:24 79.125.244.92 DATA - 250
19:29:24 79.125.244.92 QUIT - 240
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2008-11-04 19:30:46
#Fields: time c-ip cs-method cs-uri-stem sc-status 
19:30:46 216.117.220.47 HELO - 250
19:30:46 216.117.220.47 MAIL - 250
19:30:46 216.117.220.47 RCPT - 250
19:30:46 216.117.220.47 DATA - 250
19:30:46 216.117.220.47 QUIT - 240
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2008-11-04 19:32:17
#Fields: time c-ip cs-method cs-uri-stem sc-status 
19:32:17 88.246.60.162 EHLO - 250
19:32:17 88.246.60.162 MAIL - 250
19:32:17 88.246.60.162 RCPT - 250
19:32:18 88.246.60.162 DATA - 250
19:32:18 88.246.60.162 QUIT - 240
19:35:21 216.161.141.12 - - 0
19:36:09 66.196.82.7 - - 0
19:37:38 65.254.254.51 - - 0
19:50:21 216.161.141.12 - - 0
19:51:09 206.190.53.191 - - 0
19:52:38 65.254.254.50 - - 0
20:05:21 216.161.141.12 - - 0
20:06:09 66.196.97.250 - - 0
20:07:38 65.254.254.50 - - 0
20:20:21 216.161.141.12 - - 0
20:21:12 206.190.53.191 - - 0
20:22:41 65.254.254.50 - - 0
20:35:21 216.161.141.12 - - 0
20:36:13 216.39.53.1 - - 0
20:37:41 65.254.254.50 - - 0
20:50:21 216.161.141.12 - - 0
20:51:14 209.191.118.103 - - 0
20:52:41 65.254.254.52 - - 0
21:05:21 216.161.141.12 - - 0
21:06:15 209.191.118.103 - - 0
21:07:41 65.254.254.52 - - 0
21:20:21 216.161.141.12 - - 0
21:21:15 66.196.82.7 - - 0
21:22:41 65.254.254.52 - - 0
21:26:26 209.85.201.114 - - 0
21:26:26 209.85.201.114 EHLO - 0
21:26:26 209.85.201.114 - - 0
21:26:26 209.85.201.114 MAIL - 0
21:26:26 209.85.201.114 - - 0
21:26:26 209.85.201.114 RCPT - 0
21:26:26 209.85.201.114 - - 0
21:26:26 209.85.201.114 DATA - 0
21:26:27 209.85.201.114 - - 0
21:26:27 209.85.201.114 - - 0
21:26:27 209.85.201.114 QUIT - 0
21:26:27 209.85.201.114 - - 0

Open in new window

0
Comment
Question by:jasdak
1 Comment
 
LVL 40

Accepted Solution

by:
Philip Elder earned 1500 total points
ID: 22887446
www.mxtoolbox.com is the place to go to test your e-mail server settings.
Out of the box, SBS has things pretty tight.
Verify the following on your Exchange:
IMF registry setting:
http://blog.mpecsinc.ca/2007/04/sbs-exchange-2003-post-sp2-install-must.html
Greylist hiccup:
http://blog.mpecsinc.ca/2007/08/sbs-exchange-email-spam-issue-error.html
Reverse NDR Attack prevention:
http://blog.mpecsinc.ca/2008/02/smtp-server-remote-queue-length-alert.html
Philip
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Stellar Exchange Toolkit: this 5 in 1 toolkit comes loaded with mega-software tool. Here’s an introduction to tools’ usage and advantages:
Exchange administrators are always vigilant about Exchange crashes and disasters that are possible any time. It is quite essential to identify the symptoms of a possible Exchange issue and be prepared with a proper recovery plan. There are multiple…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Whether it be Exchange Server Crash Issues, Dirty Shutdown Errors or Failed to mount error, Stellar Phoenix Mailbox Exchange Recovery has always got your back. With the help of its easy to understand user interface and 3 simple steps recovery proced…
Suggested Courses

868 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question