Exchange Server Best Practices Advice for spam Explosion - TechRepublic
Question
June 13, 2007 at 08:50 AM
swinfos

Exchange Server Best Practices Advice for spam Explosion

by swinfos . Updated 19 years, 1 month ago

Good Day everybody.
I have been a Tech Republic member for many years (under a different name prior to 2004), but this is my first posting. Yee-hah

Our organization has a problem and I could use some input from the community.

We run a native Windows 2003 AD domain with Exchange Server 2003 Standard. I have a back-end Exchange server hosting 180 mailboxes and public folders. The back-end server is a dual processor w/3gb RAM, and the hostname is listed as our public MX record. I have a front end server with single processor and 2gb RAM. The front end server ONLY manages OWA for external users and we do not use POP3, HTTPS over RPC, or IMAP at this time. The back-end server handles all SMTP traffic and i have the IMF running. Additionally, the back-end is running Symantec Brightmail anti-spam and Exchange AV. Both Exchange installs are SP2.

Here is my dilemma. Until late last year I only had the Back-end server for all email and that is where I installed Brightmail. I added the front-end end server later. The good news is that i haven’t seen a single spam in over a year!!! I take this very seriously and would rather lose a legitimate message than risk garbage getting through. The organization is spoiled because we simply don’t get spam.

BUT – Until about four weeks ago I had few problems with SMTP or spam, and where Brightmail used to report about 1800 spams an hour, I am now seeing >5000 an hour. The IMF is intercepting >1500 spams an hour as well. This is causing the SMTP engine to lock up and the queues to back up. I need to reboot almost daily to break SMTP connections. In 10 years I have never seen anything like this. Spam has exploded all over the place. Otherwise Exchange is stable.

Here is my question: Obviously it is time to separate IMF SMTP and Brightmail from the Information Stores running on the same server. Disk space is not an issue.
Which would be a better path for server resources and efficiency –
A) Trade front-end/back-end roles of the servers and migrate the mailboxes to the single processor server/lower RAM server? or B)Re-install Brightmail on the single processor lower memory front end and re-direct SMTP traffic through that server and change the MX record?
My gut tells me to go with option B.

Any advice would be greatly appreciated.

This discussion is locked

All Comments