Can't see incoming mails RSS

1

Hello,

After easy installation and more than easy configuration I started the service. I send an E-Mail to a not existing recipient and was happy about the "1" on the overview page.

Unfortunately all mails are whitelisted. After a short view on the report I can see, that only outgoing mails are inspected. In this case the NBR. Can't see any entries about traffic from the internet.

ORF is installaed on a edge server (MS Exchange 2010).

Recipient validation is on via text file and before arrival.

What's wrong?

by Jens 1 month ago
2

Just for clarification:

Send from outside (private domain to business domain):
Send an E-Mail to a valid recipient: Works
Send an E-Mail to a invalid recipient: Not rejected, receive an NDR.
Send an E-Mail to a valid recipient with a blacklisted keyword: Works (sent and received)

Send from inside (business domain to private domain):
Send an E-Mail from and to a valid recipient with a blacklisted keyword: Works (sent and received)

I can see the outgoing messages only (from business to private domain) in ORF Log Viewer.

by jhoyer 1 month ago
3

Hi Jens,

are you using ORF on Exchange (which version) or with IIS?

Regards
Norbert

by NorbertFe 1 month ago
4

@NorbertFe: Hi Norbert,

we have

- Exchange 2010 (Edge) in perimeter network
- Forefront Protection 2010 for Exchange (I want to replace/extend it with ORF because it's discontinued)

Jens

by Jens 1 month ago
(in reply to this post)

5

@Jens: Hi Jens,

ok, so you installed ORF on the Edge server? The recipient validation shouldn't work at all on an edge server because there is no ldap it can connect to. Let the Exchange recipient filter do the work instead. Can you tell the order of your transport agents? Where are the whitelisted mails coming from?
You're still using FP2010? It's discontinued since years iirc 2015.

Regards
Norbert

by NorbertFe 1 month ago
(in reply to this post)

6

Norbert,
ORF is installed on the Edge-Server. Recipient validation isn't my problem.

All mails are Whitelisted. Because alle E-Mails comes from the internal Mail-Server.
No mails from the internet passed the ORF.

My test procedure:
- Sent from an external E-Mail-Account a E-Mail to my Business account. I can't see the E-Mail on the statistic and not in logfiles.
- Sent from Businesss to any extern: The statistic reflects the E-mail, the E-Mail ist whitelisted because it's from internal Mail-Server. (This decision should be right)

Jens

by Jens 1 month ago
7

Hi Jens,

if you don't see the incoming mails (from external) in the ORF logfiles, can you see them in the SMTP Logging from exchange for verification? Outbound mails are and should always whitelisted.

by NorbertFe 1 month ago
8

@NorbertFe: I can't see incomming mails from external in the ORF-Logfiles and can't see it on the overview and statistic view.
I can't see only the outgoing mail from internal in the ORF-Logfiles (and they are well whitelisted).

If you want to take a look you can find some screenshots here:
https://1drv.ms/u/s!ArEfuEx-j7okneNzB6EUfp-baIJ6hw

by Jens 1 month ago
(in reply to this post)

9

URL:
https://1drv.ms/f/s!ArEfuEx-j7okneNx4r-5qzNor3f8xQ

by Jens 1 month ago
10

Hi Jens,

do you have verbose logging on your "internet receive connector" enabled? Do you see inbound mails in them?

Regards
Norbert

by NorbertFe 1 month ago
11

@Jens: Looking at your screenshot: Thats _ALL_ backscatter. Its outbound mail. Doesn't your edge server do recipient filtering? I guess it would be easier we talk by phone on monday (you already contacted my co-worker).

by NorbertFe 1 month ago
(in reply to this post)

12

Norbert, can I send you an email? Which address do you have?
Of course we can make a call on monday. It's would be great. Which number?

We talking every time about the same problem. I know was happend, but I dont know why.

I want recipient filtering on ORF (not on Exchange) for external inbounds. And exact this point dosn't work.

by Jens 1 month ago
13

Catched!
Firewall misconfiguration published smtp protocol from internal mail server, not from edge.

Thanks Norbert, your suspicion was right.

Jens

by Jens 1 month ago
14

Hi Jens,

no problem at all. :) Hopefully you find ORF the right product for your environment. Let me know if you have any other questions.

Regards
Norbert

by NorbertFe 1 month ago

New comment

Fill in the form below to add a new comment. All fields are required. If you are a registered user on our site, please sign in first.

Nickname:
Email address (will not be published):
Your comment:

ORF Technical Support

Configuring, installing and troubleshooting ORF.

News & Announcements

Your dose of ORF-related news and announcements.

Everything but ORF

Discuss Exchange and system administration with fellow admins.

Feature Test Program

Feature Test Program discussion. Membership is required to visit this forum.

ORF Beta

Join the great bug hunt of the latest test release.

Customer Service

Stay Informed