Jump to content

Recommended Posts

Posted

Hi all,

 

I'm looking into setting our Exchange 2016 on-premise server to work with O365 hybrid. Currently, our mx records point to our Sophos UTM, which is a SMTP proxy, that relays to our Exchange Server.

 

I still want to have all email routed via our Sophos UTM, whether cloud O365 mailboxes or on premise, to take advantage of all scanning/filtering etc. I've read some threads about not being able to have anything between the Exchange Server and O365, as this will interupt mail flow (https://community.sophos.com/products/unified-threat-management/f/mail-protection-smtp-pop3-antispam-and-antivirus/102375/on-prem-exchange-migration-to-office-365-questions/398384#398384) but then other threads saying it works. Should I keep my MX records pointed to the UTM, or to O365?

 

Any help or advice greatly appreciated.

Posted

I've looked into doing a hybrid solution myself with third party SMTP filtering which then forwards to our local exchange.

My understanding is that if your using Hybrid setup, you have to use Microsoft's filtering ?

Posted
I've looked into doing a hybrid solution myself with third party SMTP filtering which then forwards to our local exchange.

My understanding is that if your using Hybrid setup, you have to use Microsoft's filtering ?

 

From what I've read, if you keep your MX records pointed to on-premise (in our case our UTM public IP), then this should work? All emails will be routed to the UTM smtp proxy, then relayed onto O365. Outbound should go via the UTM too, I think?

Posted

The connection between O365 and On prem must be 'pure' exchange to Exchange. So you have to expose your exchange servers to O365, but perhaps not the entire internet if you dont want to.

 

But you can achieve what you want no issue

 

When setting up hybrid you probably want what the wizard calles 'centralised mail routing' which basically means pump all email outgoing back from O365 to on premise, where exchange on premise will do as it sees fit with it (presumably send it to sophos box)

 

This article (great author BTW) is for something slightly differnt but touches upon centralised mail routing and even a way to have both

 

https://practical365.com/blog/exchange-multi-forest-hybrid-tips-and-tricks/

  • 2 weeks later...
Posted

I would recommend changing your MX record to point to Office365, and keep Exchange on-premise for local outgoing SMTP only.

Microsoft is a big corporation and their management of your mail is always going to be better. Especially for education, you get great value for money with Office365, security and filtering are inbuilt.

Take the strain off your in-house mail servers and offload to Microsoft.

Managing e-mail has become much easier since we migrated to Office365.

And best of all, if something goes wrong, 90% of the time we can blame Microsoft.

Posted (edited)
TBH you only need on prem exchange for the schema updates and having access to the management console. SMTP use IIS for the purpose of that traffic no point having an exchange install for that. Nothing stopping you routing your messages through an on prem box although if you are using the likes of spf/ dkim it will look like everything has been submitted from one location. Bite the bullet get shot of the sophos box and use ATP as your on prem sophos box is not throwing up a VM and detonating mail/ attachments like MS does. Edited by HPlum78

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...