Exchange 2007 Spam and Edge server

Posted on 2009-06-29
Last Modified: 2013-12-09
I have exchange 2007 setup on a single server. It is behind my firewall and I am doing a static mapping to go from the public IP to the private IP the exchange server is on. Since we switched to Exchange 2007, the spam is out of control. Outbound queue's are filling up with what looks like NDR attacks to other domains and we are constantly receiving spam such as email addressed from ourselves, to ourselves (Spoofed). With exchange 2003, I had this under control. There was the ability to control this somewhat. I could setup DNS block list and had control over NDR attacks and could check against SPF texdt records. It does not look like I can do any of this now. I have heard that if I want to do any of this, I now need a separate edge server. Could someone help me with this? If an edge server is what I need, I could use some setup advise. If that is not what I need, please tell me what I need to do. The spam is out of control.
Question by:VoyagerHealthCare
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
LVL 13

Expert Comment

ID: 24736485
You can control Spam on your Hub Role
LVL 13

Expert Comment

ID: 24736506
If you want to install the Edge is some good information on how to do this...,295582,sid43_gci1262392,00.html
LVL 13

Expert Comment

ID: 24736524
The edge role must be on a seperate server. This role can not be installed with any other role.
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 24736552
Shadowless: Thanks for the ultra fast response. I have the resources to install an edge server if it is needed, but if the script that enables the ability for me to use the HUB transport role to fight spam is just as effective as the Edge transport metthod, would it be ok to use the HUB role method, or would I get better results from the edge server method? Also, maby I could do the hub method as a temp fix until I get the edge transport server up. Thoughts?

Expert Comment

ID: 24736642
There is a range of ways of stopping spam with some ways being better than others;

Software based Solution

This is where you install an application on a PC or Server that scans the messages.
None over other solutions
The software consumes resources such as CPU and Memory and Hard Disk Capacity so your PC or servers run inefficiently.
You may get hit by a DOS or DDOS attack and your server has to handle the load.
The spam and virus are downloaded thus consume your bandwidth.
Scanning is done on the Server inside you network.  This is obviously inviting trouble into your network past your firewall unnecessarily.
The software is not future proof (A good example of this is Exchange 2003 and Exchange 2007, a lot of people will be finding their old software is not 64 bit compatible which Exchange 2007 insists on and the Software houses charge to upgrade!)
Many software based products integrate themselves so much that in the un-install guide it suggests flattening the Server and reinstalling the Operating System so this means you cant change providers easily.
Training and Updating  To install the software correctly you firstly need to understand how to use it, this represents a cost in time.
The products also need constant updating and tweaking to make them work well, again, this represents a cost in time.
Backups  There are a few problems with this, you only have email as far back as your last backup (EG Server fails at 4:30PM then you lose the best part of a days email) and someone has to remember to conduct the backup and check it worked which is more time and more money.  The other problem is that email stores are normally very large so off site solutions are either not possible or you need to spend more money on a decent backup solution.
This is a single point of failure so if the server or internet connection fails will mean lots of bounce back messages.
If you think this is right for you then GFI would be my recommendation.

Hardware based Solution
This is where you install a Hardware Firewall which handles all the scanning.
They are part or totally managed by the manufacturers.
They stop the threats before it gets onto your network.
They handle the load which frees up and speeds up your server.
Some backup your email but this is normally extra cost in most cases.
Unless you have deep pockets and buy two then you have a single point of failure and even then, if you lose your internet you still will get lots of bounce back messages.
They are traditionally expensive as there is Hardware involved and then a maintenance agreement on top.
The licenses are normally pretty rigid and you normally get roped into a support contract for updates and support
Yes they perform a backup but they still need to backed up themselves as they are still susceptible to Fire, Flood, Theft and Total Failure!
They still need some configuration which is time and money.
If you think this is right for you then PineApp or Barracuda are good.

SaaS based Solution
This is where a provider processes your email and then sends it (Relays) it to you.
They are totally managed by the provider so anyone of any technical ability can use them.
They usually have very high SLAs so you can virtually guarantee your email will be working and no bounce backs.
They work in the cloud so threats never make it to your network.
They take the load and only pass good messages to your network so your server or PC runs faster.
There is no software to install so you can have any SMTP based system and it will work.
There is no software to install so it doesnt matter if you want to change your system.
Backups are done with some providers and this is a live backup so you wont lose a message between backups or have to copy many gig of data off site each night.
Some of the emerging ones are a very cheap alternative.
They are unmanaged so leave it to the experts and get on with something else and also, stopping spam is very tedious.
Some are not highly configurable but some are so choose wisely.
If you think this is right for you then Message Labs or the one I use MailFilterUK are brilliant.
LVL 13

Accepted Solution

shadowlesss earned 500 total points
ID: 24736644
The hub will function just just as effective.  The drawbacks are that you don't have a machine on the perimeter and turning on this functionality will have some impact on your hub servers perfomance.
LVL 13

Expert Comment

ID: 24736661

You could always look at products like this for fighting spam...

Author Comment

ID: 24736729
Thanks Purple, I pretty much know all that, I was just trying to determine what my options are withing Exchange 2007. If I went with a 3rd party, I would use Spam assassin for sure.

Shadowlesss:  Thanks for your help, I think for know, I will go with the script just to stop the bulk of the spam. In the future, I would like to use Spam Assassin on the front and let that hand off to exchange.

Featured Post

Free Webinar: AWS Backup & DR

Join our upcoming webinar with experts from AWS, CloudBerry Lab, and the Town of Edgartown IT to discuss best practices for simplifying online backup management and cutting costs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
This video discusses moving either the default database or any database to a new volume.

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question