1.22.2009
Exchange Server 2007 SPAM filtering features without using Exchange Server 2007 Edge Server
IntroductionMany Exchange Server administrators know how to use features from Exchange Server 2003 which will not be available by default, if they do not use Exchange Server 2007 Edge Server Role as message hygiene server in the DMZ. This feature is only available within that role by default but can be enabled on each Exchange Server 2007 running Hub Transport Role. In this article we will have a look how to enable and configure this feature. Activating AntiSpamAgent FeatureAdding this functionality to your Hub Transport servers is a pretty simple process. First, launch the Exchange Management Shell. In the Scripts folder that was created, you will find a PowerShell script to install the Anti-spam agents. After you run this command, you will need to restart your transport service and restart the Exchange Management Console. The script we need to run is called install-AntiSpamAgents.ps1.Figure 1: Activating AntiSpamAgent FeatureAfter restarting the Exchange Transport Service, we have a new tab in Exchange Management Console available which will look like this:Figure 2: The Anti-Spam Tab of Exchange Management ConsoleNote:We will now take a closer look into each feature of Anti-Spam:Content FilteringIP Allow ListIP Allow List ProvidersIP Block ListIP Block List ProvidersRecipient FilteringSender FilteringSender IDSender ReputationContent FilteringThe Content Filter agents works with spam confidence level rating. This rating is a number from 0-9 for each message; a high SCL will mean that it is most likely spam. You can configure the agent according to the message ratings to:Delete the messageReject the messageQuarantine the messageYou can also customize this filter using your own custom words and configure exceptions if you wish.IP Allow ListWith this feature you are able to configure which IP addresses are allowed to successfully connect to your Exchange Server. So, if you probably have a dedicated mail relay server in your DMZ, you can add its IP addresses so that your server will not accept connections from other servers anymore.IP Allow List ProvidersIn general, you are unable to configure your own “IP Allow Lists” without making mistakes that will lead to problems receiving emails from your customers or any other business partners. Therefore, you should contact a public IP allow list provider which does the work for you. This would mean that you will have more quality in this service and a higher business value.IP Block ListsThis feature gives you the possibility to configure IP addresses that are not allowed to connect to your server. Contrary to “IP Allow Lists”, this feature provides a black list and not a white one.IP Block List Providers“IP Block List Providers” have been known in the past as “Blacklist Providers” too. Their task is to publish lists from servers / IP addresses that are spamming.Recipient FilteringIf you need to block emails to specific internal users or domains, this feature is the one you will need. You can configure this feature and then add the appropriate addresses or SMTP domains to your black list. Another interesting feature is that it allows you to set up the configuration so that only you will accept emails from recipients that are included in your global address lists.Sender FilteringIf you need to block specific domains or external email addresses, you will have to use this feature. You can configure a black list of what sender addresses or domains you will accept or not.Sender IDThe Sender ID agent relies on the RECEIVED Simple Mail Transfer Protocol (SMTP) header and a query to the sending system's domain name system (DNS) service to determine what action, if any, to take on an inbound message. This feature is relatively new and relies on the need of a specific DNS setting. Sender ID is intended to combat the impersonation of sender and domain also called spoofing. A spoofed mail is an e-mail message that has a sending address that was modified to appear as if it originates from a sender other than the actual sender of the message. Spoofed mails typically contain a FROM in the header of a message that claims to originate from a dedicated organization. The Sender ID evaluation process generates a Sender ID status for each message. The Sender ID status is used to evaluate the SCL rating for that message. This status can have one of the following settings:Pass - IP address is included the permitted setNeutral - Published Sender ID data is explicitly inconclusive.Soft fail - IP address may be in the not permitted set.Fail - IP address is in the not permitted set.None - No published data in DNS.TempError - transient error occurred, such as an unavailable DNS serverPermError - unrecoverable error occured, such as the record format errorThe Sender ID status is added to email metadata and is then converted to a MAPI property. The Junk E-mail filter in Microsoft Office Outlook uses the MAPI property during the generation of the spam confidence level (SCL) value.You can configure this feature to act as the following:Stamp the statusRejectDeleteSender ReputationSender Reputation is a new Exchange Server 2007 anti-spam functionality that is intended to block messages based on many characteristics.The calculation of the Sender Reputation Level is based on the following information:HELO/EHLO analysisReverse DNS lookupAnalysis of SCL Sender open proxy testSender reputation weighs each of these statistics and calculates an SRL for each sender. The SRL is a number between 0 and 9. You can then configure what to do with the message in one of the following ways:RejectDelete and archiveAccept and mark as blocked sender ConclusionAs you have seen in this article, Exchange Server 2007 provides a lot of features to increase anti-spam functionality on each Exchange Server box. If you do not use a dedicated Exchange Edge Server, you can add this functionality to Exchange Server 2007 Hub Transport as described above. If you define a configuration for your specific server design, you will not have to add third party software to meet your basic business needs.If you decide to have more than the described functions above, you should think of implementing Microsoft ForeFront Security for Exchange Servers.
1.10.2009
10 common mistakes you should avoid when flashing your BIOS
The BIOS (Basic Input/Output System) is critical to the proper operation of your computer. It is the first code that is executed at start-up and defines the way your motherboard will communicate with the system hardware components.The decision to flash your BIOS should not be taken lightly. It is essential that you do it mistake free if you still want to be able to use your computer.For the purposes of this article I am going to assume that you understand the risks of flashing your BIOS and have a good reason for upgrading your existing BIOS. If are not familiar with the basics of flashing the BIOS or if you are not 100 percent sure that flashing your BIOS is the right thing to do then please read the companion article Three Good Reasons for Flashing Your BIOS.Disclaimer: Flashing the BIOS incorrectly can lead to an unusable system. Flash the BIOS at your own risk.I have detailed ten common mistakes that are made during a BIOS upgrade listed in order from the beginning to the end of the BIOS flashing process.1. Misidentification of your motherboard make/model/revision numberIf you built your computer then you know the brand of the motherboard that you purchased and you will also likely know the model number. The revision number may be less well known to you.If you purchased your computer prebuilt, as most people do, then you probably don’t know what is under the hood. You might be able to get the information by entering the serial number of the PC on a Web site, but when it comes to flashing your BIOS you need to be 100 percent accurate and the information on the Web site could be incorrect. The only way to know for sure your motherboard make is to pop off the side panel or open the case and take a peek. (Figure A) Look for the manufacturer, model number and a revision number. (Figure B)Figure AThe motherboard make is printed on the motherboard. Do not get the name from the fans.Figure BThe motherboard model can be printed on the motherboard or as in this case, on a sticker placed on the motherboard.You can also get pertinent information from the initial POST screen. (Figure C) The first line in the upper left portion of the screen shows the BIOS maker and version. The second line shows the motherboard model, BIOS version and date. The lower left section of the screen shows the BIOS version date, motherboard model and BIOS ID.Figure C2. Failing to research or understand the BIOS update detailsEven properly researching the changes in the BIOS upgrades may not be enough to completely understand exactly what was changed. Often these BIOS upgrade notes are written by techs with little or poor knowledge of English and rarely are the details noted in full. It is not uncommon to find something similar to this.X38-002A BIOS Upgrade21/10/2007Fix to E6400 S3 resume problemThere are several issues with this. You need to know what E6400 and S3 are. Even after learning that an E6400 is an Intel Core 2 Duo CPU and S3 is one of four sleep functions in the PC’s power settings, you then need to know if you have an E6400 CPU. If you do, are you using the S3 STR (Suspend To RAM) Sleep option in Windows and having problems with it?You can’t expect your motherboard manufacturer to explain what E6400 and S3 mean, but they should be able to explain what the problem was that was fixed. Perhaps if more people requested this, more detailed information might be included in the BIOS update notes in the future.Most BIOS updates are cumulative. You will need to review all of the BIOS update notes after your current BIOS version in order to know all of the changes made with the latest upgrade version.3. Flashing your BIOS for a fix that is not neededAs you can see from the example above, it is often difficult to understand exactly what fix was implemented with a BIOS upgrade. It is equally difficult for the average PC user to determine if any of the hardware in their system is included in the fix. As a rule of thumb if your computer is operating normally, leave it alone.If you are unsure if a BIOS update will fix a problem that you are having with your PC, you can ask for more information from the manufacturer. Be 100 percent sure that the BIOS update will fix any issues that you may be having before flashing the BIOS. Hoping a BIOS update will fix a problem that you are experiencing is a poor reason to risk a BIOS flash.4. Flashing your BIOS with the wrong BIOS fileMost BIOS updates come as a zipped file containing the binary code file, the flash utility, and sometimes a README file. Flashing the erasable memory of your BIOS with the wrong code is almost certain to cause failure the next time you try to boot. Be careful when selecting the file. Many motherboard model names are similar within a single manufacturer. Download the file for the exact make/model/revision of your motherboard.The flash utility included in the download should match the BIOS manufacturer information on the initial POST screen. In the example above, I have an Award BIOS from Phoenix Technologies (Phoenix Technologies and Award merged in 1998). The older version of the Award flash utility that I received in my BIOS update file was called AWDFLASH.EXE. The latest version is called AFU869.EXE. The acronym AFU stands for the Award Flash Update Utility. It also coincidentally stands for what happens if your flash goes bad.5. Using an outdated version of the manufacturer flash utility or toolYou may be tempted to pull out the CD that came with the motherboard or computer and use the utilities on the CD to flash your BIOS. It is well worth your time to download the latest utilities from your motherboard manufacturer or computer maker. There is usually a good reason why a new version of the flash program has been made available.You will need to go to the motherboard manufacturer or computer makers Website to download the latest version of the BIOS code anyway, so plan to download the latest flashing utilities or tools at the same time.6. Not following or understanding the motherboard manufacturers specific directionsMost of you reading this article and considering a BIOS upgrade are probably of the male persuasion. Like me you probably don’t like reading and following directions. This is one time when reading and following the motherboard manufacturer instructions are essential. Each motherboard has specific steps that must be followed to have the upgrade succeed.One example of this is a jumper on some motherboards or a setting in some BIOSes that must be changed to enable BIOS memory writing.Instructions for flashing your make of motherboard can usually be found on the manufacturers Website. Specific instructions are sometimes placed in a README.txt file that comes with the BIOS flash file. Look for and read the instructions in this file carefully.If you have read all of the steps needed to flash your BIOS and there are some steps that you don’t understand, get help from the manufacturer or consider having a professional do the install for you.7. Flashing your BIOS without an UPS or at higher risk timesIt is best to flash your BIOS with a UPS installed to provide backup power to your system. A power interruption or failure during the flash will cause the upgrade to fail and you will not be able to boot the computer.Don’t assume that this can’t happen to you. I was converting the file system on the root drive on a PC once at 2:00 in the morning when I heard a loud pop outside. The lights blinked and the conversion failed. Apparently a transformer had blown in the neighborhood interrupting my power just long enough to ruin my day, or rather night. I had to reinstall the operating system from scratch.If you don’t have access to a UPS, flash the BIOS in the late evenings or when the risk of power outages are lower. Avoid flashing the BIOS during thunderstorms, windy days, high peak electrical usage, prime drive time or any other time when power outages are more likely.8. Flashing the BIOS from within Windows with other applications runningFlashing your BIOS from within Windows is universally discouraged by motherboard manufacturers. If you absolutely must flash your BIOS from within Windows and are willing to accept the additional risks involved, close all running applications and unnecessary processes. Antivirus processes running in the background are notorious for causing problems.TechRepublic has a list of services that can be disabled in XP and in Vista.9. Flashing an overclocked systemSome information I found while researching this article recommended not flashing your PC while it is overclocked. You may be able to successfully flash your overclocked system, but why take the additional risks? I don’t recommend overclocking except for the most experienced users with minimal changes and only for good reason. If you have an overclocked PC, you should be familiar enough with the BIOS to be able to reset the settings to their default values. Play it safe and throttle back.10. Failing to have a recovery plan if the BIOS flash failsWhen things go wrong it is a good idea to have a recovery plan. If your flash utility offers it, make a backup of your existing BIOS code. If this option is not available, download a copy of your current BIOS version or find a utility that will back up your current BIOS code. The original BIOS file should be on a bootable floppy with the flash utility and ready to install.Prepare in advance for a floppy read failure by making bootable backup copies to have on hand. Mark your floppies with the BIOS version to know which are the new, and which are the original versions. It is also a good idea to copy the files to a Temp directory on the hard drive to verify that the files can be read or you can run CHKDSK to verify that there are no bad sectors on the floppy.Research possible recovery options in advance and print them out. If you plan for a failure you will be less likely to panic if one occurs. If a failure does happen to you, do not turn off your computer. A failed flash means that the BIOS is likely corrupted and a reboot will fail. Keep the support number for your computer written down and available.Plan for the worst case scenario; consider keeping a backup PC handy and ready to use.The Final WordIf you have noticed some themes in this article then you are quite perceptive, patient reader:Prepare, Prepare, Prepare!Minimize the risksBecome educated and do your researchDouble and triple check your workI hope that these ten tips will aid you the next time you upgrade your BIOS. Happy flashing
1.07.2009
Managing Receive Connectors (Part 2)
In the last article we created a Receive Connector to receive mail coming from the Internet, and we also tested it using the telnet utility. In order to test a receive connector we have to be aware of the basic SMTP verbs to send a message using a telnet session. These following commands will enable you to send a test message using the telnet utility. All the basic SMTP verbs required to send a message are below:The receive connectors that we have just created is listening on port 25 and on a specific IP address. Let’s use the telnet utility to connect in our server:telnet 25Expected result: 220 Banner information Start the SMTP communication.EHLO example.orgExpected result: a list of all SMTP verbs that are accepted by the receive connector. In the first line a hello answer with the IP Address used by the sender will be shown. Define the sender of the test message.Mail from:user@example.orgExpected result: 250 2.1.0 Sender OKDefine the recipient of this test message. The SMTP domain used by the recipient must exist in the current organization. Rcpt to:user@Expected result: 250 2.1.5 Recipient OKStart the test message.Data Expected result: 354 Start mail input; end with .Hit the key twice and type in the content that will appear in the body of the test message. To finish type a period “.” in a blank line and hit .This is a test message. . Expected result: 250 2.6.0 Queued mail for deliveryClosing the session.QuitExpected result: 221 2.0.0 Service closing transmission channelWe can log on to OWA to check if the message was received. The entire process can be seen in Figure 01.Figure 01Knowing this process is important to troubleshooting mail flow and to validate a Receive Connector as well. Playing with Receive Connector security features...Now that we have just configured a Receive Connector using both the Exchange Management Console and Exchange Management Shell we can start playing with some security configurations for our Receive Connectors. All the security that we are going to see here is modified by the Receive Connector and they must be configured using the Exchange Management Shell. Let’s configure some features in our new Internet Receive Connector, as follows:Changing Banner information…Some companies do not like the idea of displaying the server name in SMTP connections. We can change the banner information used by a Receive Connector using the cmdlet below and the result will be shown in Figure 02.Set-ReceiveConnector -Banner “220 Mail Server”Figure 02If you still have Exchange Server 2003/2000 and you want to change this behavior you can use the following Microsoft KB Article: How to change the default connection response that you receive after you connect to the SMTP port in Exchange 2003.Specifying a number of errors during a session…We can control the number of protocol errors in a single session. The default value is 5, to configure it to 2 we can use the following cmdlet:Set-ReceiveConnector -MaxProtocolErrors 2Now if an SMTP Server/user connects and reaches the maximum number of errors defined in the receive connector the following message will be shown (Figure 03):Figure 03Throttling a Receive Connector…Receive connectors allow us to restrict inbound traffic to prevent high usage from a determined source, preventing an unnecessary overload of the system. Here are the three options that we have:MaxInboundConnectionsperSource: Defines the maximum number of connections made in the receive connector at the same time by the same source. This default value of this setting is 100. MaxInboundConnection: Defines how many connections the receive connector will accept at the same time. The default value of this setting is 5000. MaxInboundConnectionPercentagePersource: Based on the MaxInboundConnection value it indicates how many connections the same source can establish with the receive connector. The default value is 2%. To configure the Receive Connector using the new settings that we have just seen, we can run the following cmdlet:Set-ReceiveConnector -MaxInboundConnection -MaxInboundConnectionsperSource -MaxInboundConnectionPercentagePerSource We can also configure time-out in a receive connector in certain aspects, such as: during SMTP communication and also during an inactive connection .To configure the ConnectionTimeout we can run this following cmdlet:Set-ReceiveConnector -ConnectionTimeout To disconnect due to Inactive time, we can use the cmdlet below:Set-ReceiveConnector -ConnectionInactiveTimeout We can also restrict the number of recipients, Rate Limit and Max message size at connector level, to configure these settings we can use the following parameters:MaxRecipientsPerMessage: The maximum number of recipients in a single message, the default value is 200. MaxMessageSize: The maximum size of a message; the default value is 10MB. MaxRateLimit: This specifies the maximum number of messages that can be sent by the same client per minute. Let’s change our Internet Receive connector to accept 100 users maximum, the message size should be more than 2MB and the rate limit is 200, as follows:Set-ReceiveConnector –MaxRecipientsPerMessage:100 –MaxMessageSize:5MB –MaxRateLimit:200The last feature we will cover in this article is the TarpitIntervall. In Exchange Server 2003 we have to configure it through the Registry Editor (http://support.microsoft.com/kb/842851). In Exchange Server 2007 we can do that using the Exchange Management Shell. The tarpit feature inserts a pre-defined delay in each SMTP response that contains the 5.x.x error code during the SMTP communication between servers. The tarpit feature is only applied to anonymous connections and it should be used with the Recipient Filter Agent and Recipient Lookup features enabled.In this article we are using a single Exchange Server 2007 box with all three main roles installed (Mailbox, CAS and Hub Transport) and it is receiving messages from the Internet, we also configured the Anti-spam agents on that box (we can validate how to configure a single Exchange Server to receive internet messages and anti-spam features in this article: Configuring Mail Flow in a Single Exchange Server 2007). Let’s look at the Recipient Filtering agent and enable the Recipient Lookup feature:Open the Exchange Management Console. Expand Organization Configuration. Click on Hub Transport. Click the Anti-Spam Tab. Double click Recipient Filtering. Click the Blocked Recipients tab. Check the first option “Block messages sent to recipients not listed in the Global Address list” (Figure 04). Figure 04Okay, from now on all messages addressed to unknown address in our organization will be refused by the Exchange Server, as shown in the first rcpt to: SMTP verb in Figure 05. However we might encounter a problem where a spammer can try a harvest attack against our Exchange Server using a dictionary attack to find out which e-mails are valid in your organization. So, how can we stop it? There is no way to stop it but for each wrong address tried in the SMTP communication a “5.1.1 User unknown” error is displayed and for each of these errors we can configure tarpit to delay the server response. Figure 05The default value is 5 seconds, to change this configuration we can run the following cmdlet:Set-ReceiveConnector “” –TarPitInterval:ConclusionIn this article we have gone over how to configure some security settings and limits in a Receive Connector. We also saw that the some configuration must be done using the Exchange Management Shell. In the next article we are going to play with logging information and start playing with authentication methods and how to configure permissions using AdsiEdit.msc and the Exchange Management Shell.
Subscribe to:
Posts (Atom)