Monday, July 31, 2006

SBS 2003 SP1 won't sync AD during a Swing Migration

I was working through a Windows 2000 to SBS 2003 SP1 swing migration this weekend and when we did the dcpromo on the temp server is just would not sync AD. After digging around google for a while I found a troubleshooting guide for RPC Endpont Mapper problems. Running thought this guide showed that a bunch of ports were shutdown on the server. What???? So I checked windows firewall and sure enough it was locked down as tight as can be. Now I'm glad MSFT is securing their servers, but if I run dcpromo on a server it should open the required ports to allow it to work as a domain controller. This was a SBS 2003 SP1 server so I don't know if it is the same with a standard Windows 2003 server.

Wednesday, May 10, 2006

SonicWALL TZ170 and Exchange MS06-019

Those of you using a SonicWALL TZ170 with intrusion Prevention Service may be having issues receiving mail right now. Seems that SonicWALL released a signature at 13:39 today that is trying to combat the Exchange security flaw. Well they fixed it. They managed to shutdown all smtp traffic. You will see an error like this in your log file.

IPS Prevention Alert: SMTP Exchange Meeting Request Attempt, SID: 3233, Priority: Medium

Normally you can just disable this one alert and things would be fine, but it seems that you have to disable IPS completely to get mail flowing.

I'm on hold with SonicWALL right now..........

Wednesday, April 26, 2006

Exchange Message Limits

In today's world the default size restrictions that Exchange imposes on messages cause more trouble than they are worth. I'm not saying the limits should be removed, just reworked a little. Here's a great article to help you remember the EIGHT different locations that restrictions are configured.

http://www.msexchange.org/tutorials/Set-Size-Limits-Messages.html

Wednesday, March 01, 2006

Offer your customers a backup mail service

Matthew Huynh posted a nice little how to on setting up a backup mail server for your clients on your server. It's a nice value add that I think we may start offering to our clients.

Wednesday, February 22, 2006

In addition to RBL's

One other helpful thing to prevent an open relay is to test using one of these free open Relay test sites

http://www.abuse.net/relay.html

http://www.ordb.org/ Be careful with this one because if you fail the open relay test they will add you to their black list.