RabbieBurns Posted January 19, 2010 Posted January 19, 2010 the built in junk mail filter does a good job of moving spam to the junk mail folder, but is there a setting to set it to just delete it straight aay and not even bother putting it into the junk mail folder? Or is there a decent free spam filter that works seamless with 2010 ?
wiwo Posted January 19, 2010 Posted January 19, 2010 If you've got the MS schools agreement, try forefront 2010 for exchange. Works reasonably well at no extra cost. 1
RabbieBurns Posted February 19, 2010 Author Posted February 19, 2010 I tried the demo of forefront for exchange 2010 and it completely crippled the system. Its just a test box just now but it went from using 10% cpu and 31% of the 4gb ram, to 100% and 90% respectively. So much so that it couldnt even send or recieve any mail at all. Ive only got 4 mailboxes. Anyone got another alternative solution?
tom_newton Posted February 19, 2010 Posted February 19, 2010 If you are evaluating SchoolGuardian, you could try our anti-spam module - if you have SMTP incoming mail, it will let you just not receive the spam, tag it, or quarantine it. 1
FN-GM Posted February 19, 2010 Posted February 19, 2010 In Exchange 2007 there was a free one with it. You need to enable it in powershell. Not sure if it is still in 2010 1
RabbieBurns Posted May 2, 2011 Author Posted May 2, 2011 I was using Zen.spamhaus as a blocklist for Exchange and it was working great. I then tried Forefront for Exchange for a couple of months, and disabled spamhaus. Ive since uninstalled forefront, re-enabled the spamhaus blocklist, but Im now getting like 30 spams a day; I don't think the Zen blocklist is working properly. Is there any way to check whats going on?
sukh Posted May 2, 2011 Posted May 2, 2011 @Rabbie spamhaus blocklist is just one blacklist. Although it is maintained, it is not up to date in realtime and wont pickup new threats/AS sources unless they have been reported. Whereas using FPE 2010 uses other engines to identify AS too. FPE 2010 uses clourmark (on top of my head) and others too. I wouldn't just use spamhaus blocklist as a layer of defense from spam. This needs to be combined with configurations, such as SPF records, reverse DNS, and a commercial SPAM product. Sukh 1
RabbieBurns Posted May 2, 2011 Author Posted May 2, 2011 @sukh Its just a VM in a dev environment and FP was taking up way to much resources. Ive deleted the smaphaus entry, and readded it, and it seems to have nipped the spam in the bud, not had any today at least. Will see how it goes. We use a 3rd party appliance in production which does all spam and av etc.
bodminman Posted May 2, 2011 Posted May 2, 2011 We use a Canadian company called SmartServers.com and they're a) good b) cheap! Within 24hours of diverting our mail via them, the reports of SPAM being received into mailboxes/Junk folders ceased. They have a control panel you can log in to so that you can check mail etc and have it delivered should you wish. It's great! I think for a year we pay $550 (£350 ish) PM me if you would like any contact details.
ZeroHour Posted May 2, 2011 Posted May 2, 2011 I tried the demo of forefront for exchange 2010 and it completely crippled the system. Its just a test box just now but it went from using 10% cpu and 31% of the 4gb ram, to 100% and 90% respectively. So much so that it couldnt even send or recieve any mail at all. Ive only got 4 mailboxes. Anyone got another alternative solution? Certainly ram usage there was not thanks to forefront I would have thought because ex2010 always sucks up all the ram it can over a period of time. We had 12gb and exchange would vacum it all up. We used Puremessage and tbh for the cost it was very very good. No issues and we could run it on an smtp box separate from exchange itself which was great. 1
RabbieBurns Posted May 2, 2011 Author Posted May 2, 2011 aye, that old install was on virtualbox on a linux host which probably wasn't the wisest. It runs a lot lot better under hyper v now; FFP was actually useable. But the box only has 8gb ram in it and exchange is using 2gb; with FFP installed it was demanding 4.5gb.
ZeroHour Posted May 2, 2011 Posted May 2, 2011 aye, that old install was on virtualbox on a linux host which probably wasn't the wisest. It runs a lot lot better under hyper v now; FFP was actually useable. But the box only has 8gb ram in it and exchange is using 2gb; with FFP installed it was demanding 4.5gb. I would certainly give puremessage a try, you can set it up on an off domain smtp box running 2003 etc then just route mail through to it exchange. It also does non-mailbox checks too so mail to addresses not in exchange get deleted and cut-off before it gets to exchange which is very nice. Also try smoothwalls out as I am sure its good 1
RabbieBurns Posted May 2, 2011 Author Posted May 2, 2011 Cheers, but as I said previously, this is just a test VM in a dev environment, and only has 1 mailbox. In production we use the FortiGuard firewall appliance with the FortiMail add-on which does all our Spam needs.
sukh Posted May 2, 2011 Posted May 2, 2011 @Rabbie Both Antigen and FPE use multiple engines. I've seen cases whereby all engines have been selected and performnace settings have noe been tweaked. I'd recommend using one engine for updates and for scanning. There's a number of settings which you can play with to tweak performance. See the link below. I've used this in the past many times. Check out section 2.1 Forefront Protection 2010 for Exchange Server (FPE) Capacity Planning Guidance v. 2 - Microsoft Forefront Server Protection Blog - Site Home - TechNet Blogs I'd also use the planning tool to get a good idea on performance. Download details: Forefront Protection 2010 for Exchange Server Capacity Planning Tool Sukh 1
SYNACK Posted May 2, 2011 Posted May 2, 2011 (edited) @Rab bie Both Antigen and FPE use multiple engines. I've seen cases whereby all engines have been selected and performnace settings have noe been tweaked. I'd recommend using one engine for updates and for scanning. There's a number of settings which you can play with to tweak performance. See the link below. I've used this in the past many times. Check out section 2.1 Forefront Protection 2010 for Exchange Server (FPE) Capacity Planning Guidance v. 2 - Microsoft Forefront Server Protection Blog - Site Home - TechNet Blogs I'd also use the planning tool to get a good idea on performance. Download details: Forefront Protection 2010 for Exchange Server Capacity Planning Tool Sukh +1 FPG is great but sucks back resources like an alcoholic west aucklander sucks back bourbon. You really need to configure it to use less of the engines at a lower priority and lower the max thread count along with in some cases disabling the ailbox scanner as it checks the whole mailbox each time which as it is filtered on the way in is double handling. I have it on a VM with Exhange and 6GB of RAM (only 10-15 users) on a server with just two cores at 2GHz and it is slow in the UI but still works quick behing the scenes. You are right though that it will fight Exchange for resources. In my experience though the results were fantastic and it has to rate as one of the best systems that I have used for actual filtering ability. Edited May 2, 2011 by SYNACK 1
RabbieBurns Posted May 6, 2011 Author Posted May 6, 2011 Ive tweaked the settings and have managed to get it down to under the assigned 3GB. Thanks for the help
RabbieBurns Posted July 23, 2011 Author Posted July 23, 2011 I cant seem to find away to allow a sender permanently. Mail from a specific sender keeps getting caught in the quarantine, and I need to go in and release it. But how can I add this sender / domain to a whitelist?
SYNACK Posted July 23, 2011 Posted July 23, 2011 Is there not a whitelist in the main config console, like where you configure the local domains etc. I am no longer involved with the place that I set it up so I can't VPN in and have a look anymore.
RabbieBurns Posted July 23, 2011 Author Posted July 23, 2011 Mail - Forefront Protection 2010 for Exchange is that the only way to do it?
SYNACK Posted July 23, 2011 Posted July 23, 2011 Just found this, its user managable: Mail - Forefront Protection 2010 for Exchange and Creating an allowed senders filter list 1
RabbieBurns Posted July 23, 2011 Author Posted July 23, 2011 Just found this, its user managable: Mail - Forefront Protection 2010 for Exchange and Creating an allowed senders filter list Ive created the filter list, but it only allows has file, content, and keyword exemptions. The email is still being quarantined. The sender in question is getting quarantined for this: ID: {365AAFC7-C346-4AF4-BD00-A695F1800197} Detection Time: 7/23/2011 12:01 PM State: Quarantined as spam Incident Category: Spam Incident Name: Spam Detected using engine 'Cloudmark' File: Entire Message.eml Folder: Content Filter Agent Scan Job Name: Transport
SYNACK Posted July 23, 2011 Posted July 23, 2011 (edited) Have you set the rule to bypass for all? The other thing that I rememberd is that it adds some antispam tabs into the edge transport role in the exchange managment mmc. I think there might be a whitelist they thing buried somewhere in there as well but that is just a vague recollection and I could be wrong. EDIT: also did you reboot the edge role after you made the changes to make sure that they applied. Edited July 23, 2011 by SYNACK
RabbieBurns Posted July 23, 2011 Author Posted July 23, 2011 Have you set the rule to bypass for all? The other thing that I rememberd is that it adds some antispam tabs into the edge transport role in the exchange managment mmc. I think there might be a whitelist they thing buried somewhere in there as well but that is just a vague recollection and I could be wrong. EDIT: also did you reboot the edge role after you made the changes to make sure that they applied. Restarted the whole exchange server, selected all 3 of the options in the Filter list. Its still going into quarentine...
SYNACK Posted July 23, 2011 Posted July 23, 2011 Can you just disable that particular engine, not the best solution but it should behave with regards to following the rules.
SYNACK Posted July 23, 2011 Posted July 23, 2011 (edited) Have you tried the powershell command: Set-ContentFilterConfig -BypassedSenders [email protected] apparently that should work. You may also need to change the order the filters get applied in the EMC: Messaging Hygiene in SBS 2008 - The Official SBS Blog - Site Home - TechNet Blogs edit: http://technet.microsoft.com/en-us/library/aa995952(EXCHG.80).aspx Edited July 23, 2011 by SYNACK 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now