• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 946
  • Last Modified:

How to set up rules so Exchange only receives mails from MxLogic servers?

Hi Experts,

We use McAfee's MxLogic email protection to have them filter our mails before delivered to our Exchange server. The first couple weeks, it did a really good job. But later, junk emails probably figure out how to send emails directly to our Exchange server so now we need to lock down our Exchange server or set up firewall rules to ensure that only filtered mail from McAfee will be delivered to our Exchange server.
Can you tell me how to do that in our ASA?
 
0
Castlewood
Asked:
Castlewood
  • 4
  • 4
  • 3
2 Solutions
 
lrmooreCommented:
Setup an in bound acl that only accepts mail from trustes sources. You probably have a rule now to accept smtp from "any"

Change this:
 access-list outside_access_in permit tcp any host a.b.c.d eq 25

To this:
 access-list outside_access_in permit tcp host <mxlogic> host a.b.c.d eq 25
 no access-list outside_access_in permit tcp any host a.b.c.d eq 25

Done.
0
 
MikeKaneCommented:
Setup an ACL on your outside interface so only approved IPs can send traffic inbound to port 25 SMTP.  

You should already have an ACL on the outside, so you just need to add a few lines to it.  


access-list acl_out extended permit tcp host <ip of MxLogic> host <your email server public ip> eq smtp
access-list acl_out extended permit tcp host <ip2 of MxLogic> host <your email server public ip> eq smtp
access-list acl_out extended deny tcp any host <your email server public ip> eq smtp

This will allow the MxLogic server to speak with your email's public ip, then deny all other hosts.  

0
 
lrmooreCommented:
Also, make sure you only have one MX record for your domain, and that it points to MXLogic and not to your own public IP address a.b.c.d. You may have a secondary MX record that goes straight to you and that is where spammers will always hit first. They don't go to the primary MX host, they go for the second or third.
0
Become an IT Security Management Expert

In today’s fast-paced, digitally transformed world of business, the need to protect network data and ensure cloud privacy has never been greater. With a B.S. in Network Operations and Security, you can get the credentials it takes to become an IT security management expert.

 
lrmooreCommented:
We must have been typing at the same time, Mike!
0
 
MikeKaneCommented:
Yep - I think so.   Wouldn't be the 1st time.

And I was about to add that part about the 2nd MX record also.     Good call.
0
 
CastlewoodAuthor Commented:
Thank you for your prompt reply. You guys are awesome.
One thing though, we have some iPads/iPhones directly connecting to our Exchange server for getting emails. Do they use SMTP? Would this rule block those iPads users from accessing our Exchange server?
0
 
lrmooreCommented:
Depends. If they use OWA, or direct push then should be no problem. If they use POP3, then maybe unless you set them up to use a different outgoing smtp server or require authentication. Or have them use the VPN to access Exchange.
We might need some Exchange expertise to pop in . . .  
0
 
CastlewoodAuthor Commented:
Mike,
in your commands, you have the deny command:
access-list acl_out extended deny tcp any host <your email server public ip> eq smtp

Would this deny command void the two Permit commands and block all smtp traffic from accessing to my Exchange server ?
0
 
MikeKaneCommented:
Access lists are evaluated from the top down, as soon as the ACL finds a match, the processing stops.   So the allowed servers would match (traffic allowed) and the ACL never even evaluated the Deny statement.    The ACL as a whole will allow your mxLogic boxes and deny all else.  

>>some iPads/iPhones directly...
Normally, these devices use EWS to get mail from exchange over SSL.   I would really discourage you from opening POP ports into your exchange when you have OWA and EWS as an available and more secure alternative.
0
 
CastlewoodAuthor Commented:
I tested and found iPad has no issue receiving from my 2003 Exchange. iPad got to be using different protocol.
0
 
CastlewoodAuthor Commented:
I tested and found iPad has no issue receiving from my 2003 Exchange. iPad got to be using different protocol. BUT cannot send out since iPad use SMTP to send emails.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

  • 4
  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now