Jump to content

Recommended Posts

Posted

the built in junk mail filter does a good job of moving spam to the junk mail folder, but is there a setting to set it to just delete it straight aay and not even bother putting it into the junk mail folder?

 

Or is there a decent free spam filter that works seamless with 2010 ?

Posted
If you've got the MS schools agreement, try forefront 2010 for exchange. Works reasonably well at no extra cost.
  • Thanks 1
  • 5 weeks later...
Posted

I tried the demo of forefront for exchange 2010 and it completely crippled the system.

 

Its just a test box just now but it went from using 10% cpu and 31% of the 4gb ram, to 100% and 90% respectively. So much so that it couldnt even send or recieve any mail at all.

 

Ive only got 4 mailboxes.

 

Anyone got another alternative solution?

Posted
If you are evaluating SchoolGuardian, you could try our anti-spam module - if you have SMTP incoming mail, it will let you just not receive the spam, tag it, or quarantine it.
  • Thanks 1
  • 1 year later...
Posted

I was using Zen.spamhaus as a blocklist for Exchange and it was working great.

 

I then tried Forefront for Exchange for a couple of months, and disabled spamhaus.

 

Ive since uninstalled forefront, re-enabled the spamhaus blocklist, but Im now getting like 30 spams a day; I don't think the Zen blocklist is working properly. Is there any way to check whats going on?

Posted

@Rabbie

 

spamhaus blocklist is just one blacklist. Although it is maintained, it is not up to date in realtime and wont pickup new threats/AS sources unless they have been reported. Whereas using FPE 2010 uses other engines to identify AS too. FPE 2010 uses clourmark (on top of my head) and others too.

 

I wouldn't just use spamhaus blocklist as a layer of defense from spam. This needs to be combined with configurations, such as SPF records, reverse DNS, and a commercial SPAM product.

 

Sukh

  • Thanks 1
Posted

@sukh Its just a VM in a dev environment and FP was taking up way to much resources.

 

Ive deleted the smaphaus entry, and readded it, and it seems to have nipped the spam in the bud, not had any today at least. Will see how it goes.

 

We use a 3rd party appliance in production which does all spam and av etc.

Posted

We use a Canadian company called SmartServers.com and they're a) good b) cheap!

 

Within 24hours of diverting our mail via them, the reports of SPAM being received into mailboxes/Junk folders ceased. They have a control panel you can log in to so that you can check mail etc and have it delivered should you wish. It's great!

 

I think for a year we pay $550 (£350 ish)

 

PM me if you would like any contact details.

Posted
I tried the demo of forefront for exchange 2010 and it completely crippled the system.

 

Its just a test box just now but it went from using 10% cpu and 31% of the 4gb ram, to 100% and 90% respectively. So much so that it couldnt even send or recieve any mail at all.

 

Ive only got 4 mailboxes.

 

Anyone got another alternative solution?

 

Certainly ram usage there was not thanks to forefront I would have thought because ex2010 always sucks up all the ram it can over a period of time. We had 12gb and exchange would vacum it all up.

We used Puremessage and tbh for the cost it was very very good. No issues and we could run it on an smtp box separate from exchange itself which was great.

  • Thanks 1
Posted
aye, that old install was on virtualbox on a linux host which probably wasn't the wisest. It runs a lot lot better under hyper v now; FFP was actually useable. But the box only has 8gb ram in it and exchange is using 2gb; with FFP installed it was demanding 4.5gb.
Posted
aye, that old install was on virtualbox on a linux host which probably wasn't the wisest. It runs a lot lot better under hyper v now; FFP was actually useable. But the box only has 8gb ram in it and exchange is using 2gb; with FFP installed it was demanding 4.5gb.

 

I would certainly give puremessage a try, you can set it up on an off domain smtp box running 2003 etc then just route mail through to it exchange. It also does non-mailbox checks too so mail to addresses not in exchange get deleted and cut-off before it gets to exchange which is very nice. Also try smoothwalls out as I am sure its good ;)

  • Thanks 1
Posted

Cheers, but as I said previously, this is just a test VM in a dev environment, and only has 1 mailbox.

 

In production we use the FortiGuard firewall appliance with the FortiMail add-on which does all our Spam needs.

Posted

@Rabbie

 

Both Antigen and FPE use multiple engines. I've seen cases whereby all engines have been selected and performnace settings have noe been tweaked. I'd recommend using one engine for updates and for scanning. There's a number of settings which you can play with to tweak performance.

 

See the link below. I've used this in the past many times. Check out section 2.1

 

Forefront Protection 2010 for Exchange Server (FPE) Capacity Planning Guidance v. 2 - Microsoft Forefront Server Protection Blog - Site Home - TechNet Blogs

 

I'd also use the planning tool to get a good idea on performance.

 

Download details: Forefront Protection 2010 for Exchange Server Capacity Planning Tool

 

Sukh

  • Thanks 1
Posted (edited)
@Rab bie

 

Both Antigen and FPE use multiple engines. I've seen cases whereby all engines have been selected and performnace settings have noe been tweaked. I'd recommend using one engine for updates and for scanning. There's a number of settings which you can play with to tweak performance.

 

See the link below. I've used this in the past many times. Check out section 2.1

 

Forefront Protection 2010 for Exchange Server (FPE) Capacity Planning Guidance v. 2 - Microsoft Forefront Server Protection Blog - Site Home - TechNet Blogs

 

I'd also use the planning tool to get a good idea on performance.

 

Download details: Forefront Protection 2010 for Exchange Server Capacity Planning Tool

 

Sukh

 

+1 FPG is great but sucks back resources like an alcoholic west aucklander sucks back bourbon. You really need to configure it to use less of the engines at a lower priority and lower the max thread count along with in some cases disabling the ailbox scanner as it checks the whole mailbox each time which as it is filtered on the way in is double handling. I have it on a VM with Exhange and 6GB of RAM (only 10-15 users) on a server with just two cores at 2GHz and it is slow in the UI but still works quick behing the scenes. You are right though that it will fight Exchange for resources. In my experience though the results were fantastic and it has to rate as one of the best systems that I have used for actual filtering ability.

Edited by SYNACK
  • Thanks 1
  • 2 months later...
Posted

I cant seem to find away to allow a sender permanently.

 

Mail from a specific sender keeps getting caught in the quarantine, and I need to go in and release it. But how can I add this sender / domain to a whitelist?

Posted
Is there not a whitelist in the main config console, like where you configure the local domains etc. I am no longer involved with the place that I set it up so I can't VPN in and have a look anymore.
Posted

 

Ive created the filter list, but it only allows has file, content, and keyword exemptions. The email is still being quarantined.

 

The sender in question is getting quarantined for this:

 

ID: {365AAFC7-C346-4AF4-BD00-A695F1800197}
Detection Time: 7/23/2011 12:01 PM 
State: Quarantined as spam
Incident Category: Spam
Incident Name: Spam Detected using engine 'Cloudmark'
File: Entire Message.eml
Folder: Content Filter Agent
Scan Job Name: Transport

Posted (edited)

Have you set the rule to bypass for all?

 

The other thing that I rememberd is that it adds some antispam tabs into the edge transport role in the exchange managment mmc. I think there might be a whitelist they thing buried somewhere in there as well but that is just a vague recollection and I could be wrong.

 

EDIT: also did you reboot the edge role after you made the changes to make sure that they applied.

Edited by SYNACK
Posted
Have you set the rule to bypass for all?

 

The other thing that I rememberd is that it adds some antispam tabs into the edge transport role in the exchange managment mmc. I think there might be a whitelist they thing buried somewhere in there as well but that is just a vague recollection and I could be wrong.

 

EDIT: also did you reboot the edge role after you made the changes to make sure that they applied.

 

Restarted the whole exchange server, selected all 3 of the options in the Filter list. Its still going into quarentine...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...