programming4us
programming4us
ENTERPRISE

Using Exchange Server 2010 Antispam Tools (part 4) - IP Block and Allow Lists, Recipient Filtering , Tarpitting

- Free product key for windows 10
- Free Product Key for Microsoft office 365
- Malwarebytes Premium 3.7.1 Serial Keys (LifeTime) 2019

5. IP Block and Allow Lists

The IP Block List and IP Allow List features allow you to specify individual IP addresses, subnets, or entire ranges of IP addresses from which you will not accept or will always accept mail, respectively. Block lists are configured on a per–Hub Transport or per–Edge Transport basis. Figure 6 shows the interface for the IP Block List, but the interface for the IP Allow List is identical.

Figure 6. Configuring an IP Block List entry

In the foreground of Figure 6, you can see the interface for adding a single IP address. A nice feature of this interface is that you can specify that you always want to block an IP address, subnet, or address range or that you want to automatically unblock the address after a date and time.

6. Recipient Filtering

When recipient filtering is enabled, the Edge Transport is configured to reject mail intended for any SMTP address that is not found in the Active Directory or to reject mail intended for specific SMTP addresses. This will reduce a lot of the garbage messages for which your Exchange server accepts and then has to issue a nondelivery report. Figure 7 shows the Blocked Recipients list for the Recipient Filtering object.

We recommend that you select the Block Messages Sent To Recipients Not Listed In The Directory check box. This will help reduce the burden placed on your system by zombie networks of spammers. However, by recommending that you enable this check box, we are assuming that you have EdgeSync enabled and that all valid SMTP addresses are replicated to the Edge Transport server's local AD LDS database.

If you are performing recipient filtering, newly created mailboxes may have their mail rejected by the Edge Transport server until the replication runs again. You can force the synchronization after new mailboxes are created by running the Start-EdgeSynchronization cmdlet. Or just make sure that the users do not give anyone their email address for at least four hours after the account is created.

Figure 7. Configuring recipient filtering

7. Tarpitting

The Hub Transport and Edge Transport in Exchange Server 2010 implement a feature called a tarpit. The tarpit feature tells the SMTP server to wait a specified number of seconds (five seconds by default) before responding to a request to send a message to an invalid recipient. For example, if the recipient [email protected] is an invalid recipient in your organization, but someone's mail server sends a message to that address, your server will wait five seconds and then respond with this error:

550 5.1.1 User unknown

Now, you may wonder why this feature is even worth mentioning. Spammers often hijack people's home (or work) computers with agents that send mail on their behalf. These "bots" can offer the spammer an almost unlimited supply of SMTP clients, all sending email. They can locate your domain and then go through a dictionary of common names and try to send mail to each one for example, sending to [email protected], then [email protected], then [email protected], and so on. An Exchange server without a tarpit could send back dozens of 550 error messages each second. This makes dictionary spamming more practical.

Another evil part of the dictionary spamming attack is that the spammer can note which addresses were valid and use them in the future. This is called directory harvesting.

A five-second tarpit slows the spammer down by a factor of maybe even 500 (depending on your server's speed and your Internet connection speed) by rejecting all the invalid delivery attempts. Most spammers' software programs can't handle the rejects, and they disconnect after some period of time.

You can view your receive connector's tarpit interval by using the Get-ReceiveConnector cmdlet. For example, if you want to change the HNLEX05 Default receive connector's tarpit interval to 30 seconds, you would type this command:

Set-ReceiveConnector "HNLEX05 Default" -TarpitInterval 00:00:30

We recommend that you do not set this value to more than about 30 seconds on any of your Hub Transport or Edge Transport servers.

Other  
  •  Exchange Server 2007 Management and Maintenance Practices : Postmaintenance Procedures, Reducing Management and Maintenance Efforts
  •  Exchange Server 2007 Management and Maintenance Practices : Prioritizing and Scheduling Maintenance Best Practices (part 2) - Weekly Maintenance
  •  Exchange Server 2007 Management and Maintenance Practices : Prioritizing and Scheduling Maintenance Best Practices (part 1) - Daily Maintenance
  •  Exchange Server 2007 Management and Maintenance Practices : Best Practices for Performiming Database Maintenance (part 2) - Offline Database Maintenance
  •  Exchange Server 2007 Management and Maintenance Practices : Best Practices for Performiming Database Maintenanceng (part 1) - Automatic Database Maintenance
  •  Exchange Server 2007 Management and Maintenance Practices : Auditing the Environment (part 3) - Message Tracking
  •  Exchange Server 2007 Management and Maintenance Practices : Auditing the Environment (part 2) - SMTP Logging
  •  Exchange Server 2007 Management and Maintenance Practices : Auditing the Environment (part 1) - Audit Logging - Enabling Event Auditing , Viewing the Security Logs
  •  Qnap TS-251Turbo NAS Review
  •  Edmail See Without A Camera
  •  
    Top 10
    Free Mobile And Desktop Apps For Accessing Restricted Websites
    MASERATI QUATTROPORTE; DIESEL : Lure of Italian limos
    TOYOTA CAMRY 2; 2.5 : Camry now more comely
    KIA SORENTO 2.2CRDi : Fuel-sipping slugger
    How To Setup, Password Protect & Encrypt Wireless Internet Connection
    Emulate And Run iPad Apps On Windows, Mac OS X & Linux With iPadian
    Backup & Restore Game Progress From Any Game With SaveGameProgress
    Generate A Facebook Timeline Cover Using A Free App
    New App for Women ‘Remix’ Offers Fashion Advice & Style Tips
    SG50 Ferrari F12berlinetta : Prancing Horse for Lion City's 50th
    - Messages forwarded by Outlook rule go nowhere
    - Create and Deploy Windows 7 Image
    - How do I check to see if my exchange 2003 is an open relay? (not using a open relay tester tool online, but on the console)
    - Creating and using an unencrypted cookie in ASP.NET
    - Directories
    - Poor Performance on Sharepoint 2010 Server
    - SBS 2008 ~ The e-mail alias already exists...
    - Public to Private IP - DNS Changes
    - Send Email from Winform application
    - How to create a .mdb file from ms sql server database.......
    programming4us programming4us
    programming4us
     
     
    programming4us