Saturday, April 5, 2008

Exchange 2007 Antispam is skipped and not applied

Tricky new issue poped 6 days ago in a new Edge deployment, the issue was reported by Kashif Awan and we tried to figure it our until it is resolved.

the issue that Edge was receiving a lot of spam email. in spite of anti spam and content filtering was enabled and configured, the agent log reported the following issue:

2007-05-11T19:11:15.656Z,08C962155553DC32,172.16.1.11:25,219.91.75.121:2647,219.91.75.121,,

bpfuedz_idixm@xuite.net,vetel_djqigb@xuite.net;,qaeozfaybvgzjkvwnzwdl@ms2.hinet.net,19,

Content Filter Agent,OnEndOfData,AcceptMessage,,SCL,not available: content filtering was bypassed.

I highlighted the cause in red above, after further investigation we found an article the explains how Anti spam agent logic works:

 

http://www.maktoobblog.com/userFiles/b/u/busbar/images/1.jpg 

further details could be found on : http://technet.microsoft.com/en-us/library/aa997242.aspx

after a little troubleshooting we found that the content filtering was skipped because the receive connector was configured with Partner permission, so removing the permission and configuring only anonymous access solved the issue.

my comment: this is so weird as the documentation says the connection has to be authenticated but for somehow it didn't authenticate and applied the partner permissions.

 

No comments: