Larry Brouwer

... just my personal technology sandbox

  • About
  • Blog
  • Archives
  • Contact

Connect

  • Email
  • Facebook
  • LinkedIn

Powered by Genesis

Configuring Mailprotector CloudFilter with Windows SBS2011 Exchange 2010 “SkipMXConfig”

October 6, 2014 By Larry Brouwer Leave a Comment

Over the past several months spam has been getting out of control, so I decided to try out Mailprotector (a cloud-based email filtration solution). The specific product that I’m evaluating is their CloudFilter Total Email Security product. Configuring it was relatively easy, I just followed the instructions listed here.

I did run into a couple bumps along the way that I wanted to share with you. My first hurdle was adding users to the domain. Mailprotector has the capability to do an LDAP sync with Active Directory. However, to do this requires knowing the exact connection strings. Mailprotector does have a tutorial on the subject found here. I followed the instructions, and made a few stabs at a correct connection string. However, after several failed attempts, I searched the web, and chatted with support. Support was friendly enough, however, they didn’t have much knowledge of the subject. So I continued to work this out on my own. Searching uncovered the LDAP dsquery command. I logged onto the SBS server, and opened an Administrative command prompt. At the prompt, I issued the following command:

dsquery user ou=MyBusiness,dc=trl,dc=local

At this point, I have a list of all the users defined in the Active Directory. The user that I’m mainly interested in is the Network Manager account:

“CN=Network Manager,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=trl,DC=local”

This is the User Distinguished Name that I need to use for authentication within Mailprotector. To test out the connection string, I opened a console window on my Mac and issued the following command:

ldapsearch –h my.ip.add.ress:389 –x –D “CN=Network Manager,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=trl,DC=local” –b “DC=trl,DC=local” –W

This yielded a list of users defined in Active Directory, which is just what I wanted to see.

With this in hand, I was able to set up the LDAP sync with Active Directory into my SBS2011 Exchange 2010 Server. One thing to keep in mind is to be sure to keep the “double quotes” around the Distinguished Name string. My first attempt didn’t have the double quotes, and it didn’t work. The second parameter needed is the search base. Here I just used the default format as shown in the tutorial:

DC=trl,DC=local

Here’s screen shot of my configurations:

image

After adding users to the domain, the next step is to configure the domain by changing MX records to point to Mailprotectors CloudFilter server. This usually has to be done with your domain registrar. In my case this is GoDaddy. Mailprotector has a tutorial on doing this here. The update process was supposed to be relatively easy. Just log into GoDaddy and delete the existing MX record, and add in the 4 new MX records that Mailprotector provided. In my case the 4 records are:

image

Here’s the configuration within GoDaddy:

image

Looks easy enough, right? Well this is where the second bump in the road occurred. Upon saving, the new MX records seemed to be there for a few minutes, and then would go away, and return back to the original MX record. After a few attempts with the same result, I decided to start searching for an answer. It wasn’t very long before I ran across this post which led me to this post. I vaguely remember when originally configuring SBS2011, something about having all the DNS records automatically configured by the server, and that GoDaddy was one of the domain registrars that it worked with.

In any case, the fix involves adding a new registry DWORD (32-bit) Value, “SkipMXConfig”, with a value of 1 located at: HKEY_LOCAL_MACHINE\Software\Microsoft\SmallBusinessServer\Networking\Services

image

Once I put this in place, I rebooted the server to make sure the new setting took effect. This solved the issue, and Mailprotector started filtering email.

Mailprotector also recommends locking down the network and configuring exchange to only accept email from the Mailprotector server. The instructions are found here. I am deferring this task for the moment and will update this post as I get time to do so.

… A couple days later. I’m still getting a ton of spam, so I’m now continuing on with configuring the Exchange server to only accept email from Mailprotector. The tutorial can be found here. The examples don’t show Exchange 2010, however, it’s pretty much the same as Exchange 2007. Here’s a screen shot of my configuration changes:

image

That’s pretty much it for the initial configuration! I will continue to update this post as I gain more knowledge and experience with Mailprotector’s CloudFilter product.

Filed Under: Notable Tagged With: Exchange 2010, SBS2011, Spam

SmarterMail Security Lockdown Procedures

May 5, 2010 By Larry Brouwer Leave a Comment

I spent most of the afternoon tracking down a problem with my web server. Performance came to a standstill. So I went into Task manager and found the MailService.exe process was maxing out resources. I rebooted, and found that it would gradually start taking more and more resources until the system became virtually unusable. Within 20 minutes after a reboot of the system, it would be hogging most of the memory, and max out the CPU to 100%. I also looked through the event Application logs. Searched for ‘mail’. Found errors “System.OutOfMemoryException: Exception of type ‘System.OutOfMemoryException’ was thrown.”.

I then Googled on ‘mailservice.exe memory System.OutOfMemoryException’ and found this post on SmarterTools Forums – MailService.exe memory reporting issue in 6.5. Many users seem to be experiencing this problem. A second post from the SmarterTools Forums – HELP! SmarterMail.exe keeps failing every few hours also indicates that this is a Microsoft .Net issue. They refer to the prior post stating the fix is to re-install Microsoft .Net. I’ve already attempted this procedure before. See my prior post 2010-04-23 Notes for the day.

[Read more…]

Filed Under: Notable Tagged With: Security, SmarterMail, Spam

Recent Posts

  • Weaver’s Bamboo “Bambusa textilis” clumping bamboo for sale
  • configuring NTP Service on FreeNas, XenServer, and virtualized Windows Server 2012 R2 Domain Controller
  • CentOS 7 Warning: Your Magento folder does not have sufficient write permissions.
  • AOE Scheduler 1.3.0 cron issue with Magento 1.9.2.2

Tag cloud

Log Parser SSMS PrestaShop Azure Neptune Google Analytics web.config SmarterMail Windows 7 Blogs BlogEngine.Net AWStats Tools clumping bamboo Security D-Link iframe PST Live Writer OfficeLive Spam Scanpst.exe redirect eCommerce SMTP Linux SSL Windows Remote Desktop OpenCart TomatoCart SVN Yahoo Mail Outlook 2007 .NET Framework Outlook Connector CentOS Maytag IIS7 DIR-655 Database Mail Comcast Magento SqlServer DotNetNuke mstsc.exe