GrumbleDook Posted April 12, 2011 Posted April 12, 2011 @Willott - It does depend on a number of factors. If inbound emails are screen by your county, then you have one layer of defense. To route emails from your Exchange Org to Smoothwall and then do address-rewrite, can cause issues. I know you say you have this running, but I haven't seen this type of set-up before, except for relays within your AD which may be relaying from a SMTP server with no AV/AS. This is how email filtering is delivered across a whole hosted email platform for one RBC, and with no problems. It is quite an effective method to be honest and we are still trying to explore what the load would be if it was opened up to more schools the same way @willot used to do it. For one, it would save schools with in house mailservers from having to buy another filtering solution to deal with user to user emails.
eddyc Posted April 12, 2011 Posted April 12, 2011 We use FPE 2010 for Exchange 2010. It's included in the volume licensing agreement, does keyword as well as virus scanning - can forward bad mail to a specified address and seems to do a very good job of it!
sukh Posted April 12, 2011 Posted April 12, 2011 This is how email filtering is delivered across a whole hosted email platform for one RBC, and with no problems. It is quite an effective method to be honest and we are still trying to explore what the load would be if it was opened up to more schools the same way @willot used to do it. For one, it would save schools with in house mailservers from having to buy another filtering solution to deal with user to user emails. Like I say it can work but what about Having AV/AS on the Exchange Server can also provide additional checks/scans on the mailstores themselves. What if an email in your mailbox is effected with a virus, or in your store? What if you use PF databases are infected? RBC? Sukh
Willott Posted April 13, 2011 Posted April 13, 2011 Regional Broadband Consortium. @sukh - if a single email is infected with a virus, this can only be transferred/do damage if it is opened on a client machine (which should have centrally managed AV) or if it's sent in an email (which would go via external filtering/scanning which would detect virus and remove). The other thing to consider is how a virus would get there - intentionally attached to an email within a mailbox from an unprotected machine? Even if it somehow ended up trying to run on the Exchange server, this should be when a standard AV would pick it up (obviously standard AV with execptions for the Exchange databases) - but how would it end up running on the Exchange server?
sukh Posted April 13, 2011 Posted April 13, 2011 @Willott - I would hope too that some sort of AV is deployed on the desktops to caputure the virus if it's opened and depending on the AV on the desktop and config, if AV is configured to stop mass mail on port 25. Also, depends on sites you are browsing and if the your web proxy content is good enough to pick mass mail viruses, again this comes down to your desktop AV to stop mass mail on 25. Even if you were infected and the email would go to your external filtering/scanning, the impact this will have on your exchange server will have a serverr performance hit. In addition to the performance hit, your transactions logs will genertaed excessively which will bring down your Exchange stores. As an example, I have seen customers who have had calendar appoinments in their mailbox which have had some vbs code in them, this message was never detected by AV/filtering and all of a sudden, when the message re-occuring appointment 'poped up' this caused to generate emails within the EDB itself, so you could not track the message via MT. This did not send emails to others but just generated 40 transaction logs per min for that mailbox. Which caused Exchange stores to dismount. When this user was sending genuine appointments to others users within the office, this issue multipled bringing dowm more exchange servers and storage groups. Having AV scanning inside the mailstore/database found this. This is why I recommend at least weekly scans for your stores. Sukh
tom_newton Posted April 13, 2011 Posted April 13, 2011 Just caught up on thees thread. For the smoothie speculators, we do an SMTP/PoP proxy. You could probably reroute internal mails through it, though I don't recall anyone who is doing that. "Zap" is the name )which we are trying to retire as it is hardly descriptive) for a module which provides the two proxies. Mailshell provides anti-spam/phishing capability to this module, and VIPRE the anti-malware. There's no cyber-bullying rules... yet.
john Posted April 13, 2011 Posted April 13, 2011 "Zap" is the name )which we are trying to retire as it is hardly descriptive) Oh no please don't I like that name as it Zaps the Spam and Viruses, I think its a great name
tom_newton Posted April 13, 2011 Posted April 13, 2011 Oh no please don't I like that name as it Zaps the Spam and Viruses, I think its a great name I think it was George's name originally... no-one else had anything better at the time
GrumbleDook Posted April 14, 2011 Posted April 14, 2011 I think it was George's name originally... no-one else had anything better at the time That's it ... blame management ... it is always their fault! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now