Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Exchange 2003 Authentication Advice

Posted on 2013-05-15
1
Medium Priority
?
158 Views
Last Modified: 2013-06-30
HI, Looking for advice here as I am in uncharted waters, for me , anyway... Been doing these pci compliance scans and up till recently we have been ok - then they add something new that they say is a problem, we fail the test, we fix the problem and then we pass - -the cycle goes on like this and just this week we got a Clear Text password issue on port 25.... So after trawling I found a sembee response to exactly this question and as advised , turned off all authentication except anonymous - and the scan passed the test.

I am happy that it passed the test but am unsure of exactly what was done - because it was through the night,  -i.e. if this had been done through the day time, would it have disabled email to the users, what would not have worked - we have web shops that use the mail server to relay email receipts to anyone purchasing goods -I am assuming that these would have failed?

While the switching off of authentication passed the test, for which I am grateful - is there a longer term permanent solution to this issue (and no doubt the scanning company will hit me with others in a couple of months)

Also , has anyone managed to get away from these scanning companies - we tried but they told us we were non compliant when we let the contact lapse - and then got charged by the bank.... all advice welcome - thanks
0
Comment
Question by:pabby0612
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 19

Accepted Solution

by:
Miguel Angel Perez Muñoz earned 2000 total points
ID: 39170695
I will to try tell you how this works, I´m not native english but let´s go:

Exchange uses 25 TCP port (SMTP) by default to get emails from other mail servers. Since you let get mails anonymously, you are letting this remote servers place emails on your servers. Thats is ok, and there is normal Exchange operation.
But maybe you require your remote users send emails to other emails servers, (relay) anonymously you must to block, because your Exchange server not let send mails to other servers without authentication. If you permit your server act as open relay, spammers will use your server and your server will be marked as spam sender, and this is not good deal.
How to prevent this?, let your authenticated users to relay. How? I recommend you create another SMTP server and configure authentication (whatever secured) and uses other port different of 25 (p. ex 2225).
0

Featured Post

Tech or Treat!

Submit an article about your scariest tech experience—and the solution—and you’ll be automatically entered to win one of 4 fantastic tech gadgets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Granting full access permission allows users to access mailboxes present in their database. By giving full access permission one can open and read the content of any mailbox but cannot send emails from that mailbox.
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question