Pages

Friday, January 27, 2012

How to Configure a Relay Connector for Exchange Server 2010

In most Exchange Server 2010 environments there will be the need to allow relaying for certain hosts, devices or applications to send email via the Exchange server. This is common with multi-function devices such as network attached printer/scanners, or applications such as backup software that send email reports.

SMTP communication is handled by the Hub Transport server in an Exchange organization. The transport service listens for SMTP connections on it’s default Receive Connector. However, this connector is secured by default to not allow anonymous connections (ie, the type of connection most non-Exchange systems will be making).

You can see this in effect if you telnet to the server on port 25 and try to initiate unauthenticated SMTP communications.

220 EX3.exchangeserverpro.local Microsoft ESMTP MAIL Service ready at Wed, 18 Au
g 2010 19:42:27 +1000
helo
250 EX3.exchangeserverpro.local Hello [192.168.0.9]
mail from: somebody@hotmail.com
530 5.7.1 Client was not authenticated

For some Hub Transport servers that are internet-facing, anonymous connections may already be enabled. In those cases relay would still be denied but will behave differently than the first example.

220 EX3.exchangeserverpro.local Microsoft ESMTP MAIL Service ready at Wed, 18 Au
g 2010 20:01:44 +1000
helo
250 EX3.exchangeserverpro.local Hello [192.168.0.9]
mail from: somebody@hotmail.com
250 2.1.0 Sender OK
rcpt to: somebody@gmail.com
550 5.7.1 Unable to relay

You’ll note that relay is denied if I try to send from an @hotmail.com address to an @gmail.com address, because neither is a valid domain for the Exchange organization. But with Anonymous Users enabled on the Receive Connector I can send from an @hotmail.com address to a valid local address.

220 EX3.exchangeserverpro.local Microsoft ESMTP MAIL Service ready at Wed, 18 Au
g 2010 20:05:54 +1000
helo
250 EX3.exchangeserverpro.local Hello [192.168.0.9]
mail from: somebody@hotmail.com
250 2.1.0 Sender OK
rcpt to: alan.reid@exchangeserverpro.local
250 2.1.5 Recipient OK
data
354 Start mail input; end with .
test
.
250 2.6.0 [In
ternalId=2] Queued mail for delivery

However if I try to relay out to an external recipient, the Exchange server does not allow it.

220 EX3.exchangeserverpro.local Microsoft ESMTP MAIL Service ready at Wed, 18 Au
g 2010 20:11:27 +1000
helo
250 EX3.exchangeserverpro.local Hello [192.168.0.9]
mail from: backups@exchangeserverpro.net
250 2.1.0 Sender OK
rcpt to: alerts@managedserviceprovider.com
550 5.7.1 Unable to relay

To permit a non-Exchange server to relay mail we can create a new Receive Connector on the Hub Transport server. Launch the Exchange Management Console and navigate to Server Management, and then Hub Transport. Select the Hub Transport server you wish to create the new Receive Connector on, and from the Actions pane of the console choose New Receive Connector.


Give the new connector a name such as “Relay ” and click Next to continue.


You can leave the local network settings as is, or optionally you can use a dedicated IP address for this connector if one has already been allocated to the server. Using dedicated IP addresses for each connector is sometimes required if you need to create connectors with different authentication settings, but for a general relay connector it is not necessary to change it.


Highlight the default IP range in the remote network settings and click the red X to delete it.


Now click the Add button and enter the IP address of the server you want to allow to relay through the Exchange server. Click OK to add it and then Next to continue.


Click the New button to complete the wizard.

The Receive Connector has now been created but is not yet ready to allow the server to relay through it. Go back to the Exchange Management Console, right-click the newly created Receive Connector and choose properties.

Select the Permission Groups tab and tick the Exchange Servers box.


Select the Authentication Tab and tick the Externally Secured box.


Apply the changes and the Receive Connector is now ready for the server to relay through.

220 EX3.exchangeserverpro.local Microsoft ESMTP MAIL Service ready at Wed, 18 Au
g 2010 20:31:00 +1000
helo
250 EX3.exchangeserverpro.local Hello [192.168.0.9]
mail from: backups@exchangeserverpro.net
250 2.1.0 Sender OK
rcpt to: alerts@managedserviceprovider.com
250 2.1.5 Recipient OK
data
354 Start mail input; end with .
test
.
250 2.6.0 <924bab1e-0f07-4054-8700-d121577993b4@EX3.exchangeserverpro.local> [In
ternalId=3] Queued mail for delivery

Because the remote IP range has been secured to that single IP address, any other servers on different IP addresses still won’t be able to relay through the Exchange Server. From any other IP address not included in the remote IP range on the Receive Connector relay will be denied.

220 EX3.exchangeserverpro.local Microsoft ESMTP MAIL Service ready at Wed, 18 Au
g 2010 20:46:06 +1000
helo
250 EX3.exchangeserverpro.local Hello [192.168.0.2]
mail from: backups@exchangeserverpro.net
250 2.1.0 Sender OK
rcpt to: alerts@managedserviceprovider.com
550 5.7.1 Unable to relay

You can later add more IP addresses, IP ranges, subnets, or even add multiple IP addresses to the Receive Connector using a script if necessary.

Source


http://exchangeserverpro.com/how-to-configure-a-relay-connector-for-exchange-server-2010

Friday, January 20, 2012

Configuring multiple E-mail domains in exchange 2010

We can configure Microsoft Exchange Server 2010 to accept e-mail for more than one SMTP domains. In this article I will show you how to configure the accepted domains and how to create the new email address policy for the new e-mail domain

Scenarios:-

  • Your Company has different independent business units and the each of them need different e-mail domains; company management doesn’t want to spend money for this.
  • You Providing the email hosting service and have to accept e-mail for more than one SMTP domain name

Prerequisites

  • A public DNS MX resource record is required for each SMTP domain for which you accept e-mail from the Internet. Each MX record should resolve to the Internet-facing server that receives e-mail for your organization.
  • Send and Receive connectors should be configured, so that the Exchange organization can send e-mail to and receive e-mail from the Internet.

There are two steps to configure exchange 2010 to accept e-mail for more than one SMTP domains. The initial step is configuring the accepted domain and the second one is create or modify the email policy.

Use the EMC to configure Exchange 2010 to accept e-mail for more than one domain

Expand the Organization Configuration node, and then click Hub Transport. In the results pane, click the Accepted Domains tab.

In the action pane, click New Accepted Domain, or right-click and select the New Accepted Domain from the Accepted Domains tab. Then the New Accepted Domain wizard appears.

1

Figure: 1

On the New Accepted Domain page, type a name to identify the accepted domain entry. In the Accepted Domain field, type the SMTP domain name. Select Authoritative Domain. E-mail is delivered to a recipient in this Exchange organization.

Click New to create the Accepted Domain.

2

Figure: 2

Now you can see that the Authoritative Accepted Domain shareef.info has been created and listed in the Accepted Domain tab

3

Figure: 3

Now we need to configure the email address policy for the newly created authoritative domain. To do this either we can create new email address policy or edit the existing email address policy. I prefer to create the new email address policy.

To create the new email address policy expand the Organization Configuration node, and then click Hub Transport. In the results pane, click the E-mail Address Policies tab.

In the action pane, click New E-mail Address Policy or right-click and select the New E-Mail Address Policy from the E-mail Address Policies tab.

4

Figure: 4

Type a name for the e-mail address policy in this example its @shareef.info. If the users that will be assigned this new e-mail address policy are all in a specific organizational unit (OU), click Browse to restrict this e-mail address policy to that specific OU. Select an option under Include these recipient types to determine to which recipient types this e-mail address policy will be applied, in this example I choose Users with Exchange Mailbox, you can select this option as per your exchange environment. Click Next.

5

Figure: 5

If you want to specify any condition for this policy specify the same. In this example I prefer not to specify any condition. Click Next to continue.

6

Figure: 6

On the E-mail Addresses page, click Add to specify the domain for the E-mail Address and the E-mail address local part.

7

Figure: 7

In the SMTP E-mail Address dialog box, select the option under E-mail address local part that determines how the recipient’s e-mail address alias will be generated.

Click the Select the accepted domain for the e-mail address option, and then click Browse. In the Select Accepted Domain dialog box, select an accepted domain, in this example its shareef.info and then click OK. Click OK again to close the SMTP E-mail Address dialog box.

8

Figure: 8

Click Next to continue.

9

Figure: 9

In the Schedule page, select an option to specify when the e-mail address policy will be applied and the maximum length of time that the task is permitted to run. I am choosing immediately.

Click Next.

10

Figure: 10

Click New to create the new E-Mail Address Policy

11

Figure: 11

The New E-Mail Address Policy task has been completed successfully. Click Finish to exit the wizard.

12

Figure: 12

In this screenshot you can see the new email address policy has been applied.

14

Figure: 13

PowerShell commands for configuring the Exchange 2010 to accept e-mail for more than one domain

To create the New Authoritative Accepted Domain

New-AcceptedDomain -Name “blog.shareef.info” -DomainName shareef.info -DomainType Authoritative

To create the New E-Mail Address Policy

New-EmailAddressPolicy -Name “@shareef.info” -IncludedRecipients UserMailbox -ConditionalDepartment “Fourth Coffee” -Priority 1 -EnabledEmailAddressTemplates “SMTP:@fourthcoffee.com”

To apply the New E-Mail Address Policy to the recipients

Update-EmailAddressPolicy -Identity “@shareef.info”

Source

http://blog.shareef.info/2010/06/02/configuring-multiple-e-mail-domains-in-exchange-2010/

http://technet.microsoft.com/en-us/library/aa996314.aspx

Configure Exchange 2000/2003 to Receive E-Mail for other Domains

How do I configure my Exchange 2000/2003 server to accept e-mails for domains other than my own?

Exchange 2000/2003 will only accept e-mail traffic for the e-mail domain that is identical to the name of your Active Directory domain. However sometimes we would like to allow our Exchange server to also receive e-mail for domains other than our own, internal domain name.

For example, if you have an AD domain called TEST.HOME and you've installed Exchange 2000/2003 on it, each and every mailbox enabled user, mail enabled user, mail enabled group, mail enabled contact and mail enabled Public Folders you have will automatically have an e-mail address of ALIAS@TEST.HOME.

One day you've decided that you'd like to have an Internet presence, so you bought TEST.COM and you'd like to begin using it on your Exchange server. You don't need to rename your AD domain for that, but you DO need to configure Exchange to receive e-mail for the new domain, along with the traffic you might have had for the old domain name.

This example can also be extended to instances where a company has had it's Internet domain name changed, or when one Exchange server is used to host mailboxes for more than one company.

Basically, Exchange can handle hundreds of mail domains without any problem (up to about 1000 domains), so performance is usually not an issue.

In all of the above examples you'll need to configure Exchange to use new (or modified) Recipient Policies to reflect the change in the e-mail domain names.

Note: You can also configure only a specific range of recipients to receive the new e-mail address. That topic is covered in the Configure Specific E-Mail Addresses for Specific Exchange 2000/2003 Users article.

In order to create a new Recipient Policy please perform the following steps:

  1. Open the Exchange System Manager.
  2. Navigate to the Recipients folder, expand it and go to Recipient Policies. Right-click Default Recipient Policies and choose Properties.

Note: You can also create new Recipient Policies instead on modifying the Default Recipient Policy. You will want to do that in cases when you want to choose specific users or recipients on whom you'd like the new policy to apply. That topic is covered in the Configure Specific E-Mail Addresses for Specific Exchange 2000/2003 Users article.

  1. Click on the E-Mail Address Policy tab. Notice how the default SMTP E-Mail address suffix is exactly the same as your AD Domain. This is where we want to add the new domain.

  1. On the E-Mail Address Policy tab you can add all sorts of e-mail addresses, but the most common one is SMTP of course. Click New, choose SMTP and then configure your Internet E-Mail Domain name (the one you plan to add to all your Exchange recipients - users, groups, contacts and Public Folders).

Remember to add a "@" sign before the new domain name.

You can also select the new e-mail address to be the primary address (i.e. in bold, and it will be used as the e-mail address to where the replies to messages sent by your users will be sent).

Make sure you place a V in the checkbox near the new domain name, otherwise this policy will not make any changes to your recipients.

Note: You can add as many e-mail domain names you want (you should of course OWN them...duh) and the policy will configure them all.

Lamer Note: No, entering "kuku.co.il" is not what YOU'RE supposed to do, this is just an example. You need to BUY your OWN domain name and then have it configured to send e-mail traffic to YOUR server. Read the Configure MX Records for Incoming SMTP E-Mail Traffic article for more info on this topic.

When you're done click Ok.

  1. Read the Exchange System Manager message that pops out and click Ok. Basically, this message tells you that if you plan to make changes to this filter you should then run the Apply Policy Now option.
  1. After you've set your policy, you will now need to apply it. Right-click it and select Apply this Policy Now.

  1. In order to make things happen faster, you'll want to re-run the Recipient Update Service - or RUS - (both of them in most cases, all of them in case you have more than one AD domain). Go to the Recipient Update Service folder and in the right pane right-click all the instances of the RUS you see, and select Update Now.

  1. In order to test the success of the new Recipient Policy, go to one of your recipients and see if the new e-mail address is listed in the recipient's properties.

Done! In cases where the new e-mail address we've just configured is a sub-domain of your current existing domain you'll need to contact your ISP or Name Server provider and ask them to add a sub-domain to your existing domain.

In cases where the new address is for a totally different domain you'll need to configure the MX Records for the new domain. Without performing this step no one will ever know that your server is in fact serving this new domain. Read my Configure MX Records for Incoming SMTP E-Mail Traffic article for more info on this subject.

You can also test to see if your Exchange server is in fact willing to accept messages destined for this new domain. The best methods of testing can be found in the SMTP, POP3 and Telnet in Exchange 2000/2003, Send Mail from Script and Test SMTP Service in IIS and Exchange articles.

Links

You Cannot Deliver Mail to the Local Domain After You Change the Default Recipient Policy - 819421

Source

http://www.petri.co.il/configure_exchange_2000_2003_to_receive_email_for_other_domains.htm