Solved

SMTP call-ahead for recipient validation

Posted on 2014-02-12
2
2,113 Views
Last Modified: 2014-02-21
We have two Cisco IronPort C360 appliances doing antispam and antivirus filtering before mail makes its way into Exchange. These have not been in a DMZ, and we're now making the effort to move these into a DMZ.

We use our corporate AD servers for LDAP recipient validation (so that invalid recipients are dropped). We were planning to move an LDAP server into the DMZ with the appliances, with email addresses pushed to it from production, for recipient validation. *BUT* I came across SMTP call-ahead, which seems like it would suit our needs better since we wouldn't need a dedicated LDAP server and our architecture would be more secure...

IronPort would open an SMTP session to Exchange to verify the recipient. Exchange hub servers don't do this out of the box, antispam agents need to be installed. This fellow has a good guide: This fellow has a good guide: http://www.jjclements.co.uk/2010/09/23/exchange-2010-recipient-filtering-on-a-hub-transport-server/

I'm wondering if what we're doing is a terrible idea. Does anyone have any experience with SMTP call-ahead? I would appreciate any thoughts, validation, or feedback.
0
Comment
Question by:msghydron
2 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39854028
I enable recipient filtering on all servers that I deploy and it is something I think should be on all email servers.
The problem you will have is that Exchange has tarpit enabled by default, which can cause email delivery days. It will depend on whether the appliances are able to cache the results or not (I haven't used them myself, so don't know). If they are able to cache results then it shouldn't be a problem, as they will only have the tarpit delay the first time they connect. However if they are doing it "live" each time, then you may well have to reconfigure Exchange to remove the tarpit.

Simon.
0
 

Author Closing Comment

by:msghydron
ID: 39878382
We are proceeding with SMTP call-ahead on the IronPort C360 appliances, switching from LDAP recipient validation. We've removed the 5-second tarpit delay. I think this is a better configuration, when the C360's are in a DMZ.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now