CONNEXUS

SEARCH SUPPORT DESK

Connexus Support Centre

SafeMail Support

The Connexus SafeMail servers are configured to block Spam and Viruses destined for your mail server. By blocking access to external mail servers we ensure that Spam and Viruses cannot bypass the SafeMail server and access your mail server directly.

The following guides demonstrate how to configure your mail servers and firewalls to allow mail only from Connexus SafeMail servers.

SafeMail and Norton Internet Security

Configuring Norton Internet Security to work with SafeMail


hr

SafeMail and Microsoft Exchange

Open Exchange System Manager,
Expand, navigate and select ‘Default SMTP Virtual Server’

Select ‘Action’ from the menu bar
Select ‘Properties’

Select the ‘Access’ tab
Select the ‘Connection’ icon

Select the ‘Only the list below’ radio option
Select the ‘Add’ icon

Select the ‘Group of computers’ radio button

Enter into ‘Subnet address’:
203.12.22.0

Enter into ‘Subnet mask’:
255.255.255.0

Continue and add all your local area network (LAN) addresses

hr

SafeMail and Norton Internet Security

Open Norton Internet Security and click on the Norton Internet Security tab.

Click on Personal Firewall and select Configure.

Select Configure in the General Rules section.

We wish to allow only the mail coming from Connexus SafeMail servers (203.12.22.1 – 203.12.22.254) on port 25. Click on Add to create a new ‘allow’ rule.

Select Allow and click on Next.

Select Connections from other computers and click Next.

Select Only the computers and sites listed below and click on Add.

Enter the details as shown below. This will ensure mail sent from SafeMail will be allowed to reach your mail server. Click on OK.

You should now see the Connexus IP range in the box. Click on Next to continue.

Now we need to ensure that only port 25 is allowed. Select Only communications that match all types and ports listed below and click Add.

Click Known ports from list and tick port 25 SMTP, then click on OK.

You should now see local smtp (port 25) in the box, click on Next.

Leave the box unticked and click on Next.

Name the rule “Allow mail from Connexus” and click on Next.

The rule for Allowing mail from Connexus SafeMail servers has been created.
Click on Finish to save the rule.

Now that we have allowed SafeMail to send us mail we wish to block other mail servers from sending us mail. Click on Add to create a new ‘deny’ rule.

This time we need to Block other mail servers.

Select Any computer and click on Next. This will ensure that all other mail servers are blocked.

We need to ensure that port 25 is blocked specifically. Select Only communications that match all types and ports listed below and click on Add.

Click Known ports from list and tick port 25 SMTP, then click on OK

Leave the box unticked and click on Next.

Name the rule eg “Block all other mail servers” and click on Next.

The rule for Blocking all mail servers apart from Connexus SafeMail has been created. Click on Finish to save the rule.

Both rules have now been setup. Click on OK and OK on the next screen to exit Norton Internet Security.

hr

SafeMail and ZoneAlarm

Open Zone Alarm and click on the Firewall tab on the left hand side.

Click on the Expert tab.

We wish to allow only the mail coming from our SafeMail servers on port 25. Click on Add to create a new ‘allow’ rule. To enter the IP Range into the rule click on Modify in the Source box and then select IP Range from the menu as shown below.

Enter the IP range 203.12.22.0 to 203.12.22.254, this will allow SafeMail to send mail to your mail server.

To ensure we are only allowing mail on port 25 click on the Modify button in the Protocol section.

Select SMTP in both the Destination and Source Ports and click on OK.
This completes the setup for allowing SafeMail to communicate with your mail server. Click on OK again to return to the Expert mode.

Now that we have allowed SafeMail to send us mail we wish to block other mail servers from sending us mail. Click on Add to create a new ‘block’ rule and this time we only need to modify the Protocol section to block port 25.

Again select SMTP in both the Destination and Source Ports and click on OK.

You should now see both rules setup in the Expert section of Zone Alarm.

hr

SafeMail and McAfee

Open McAfee Security Center and Select Internet & Network. Click on Configure to modify the firewall settings.

Select the Firewall section and click on Advanced.

As McAfee does not have the ability to block IP addresses or specific ports we recommend using the Stealth Security Level for your mail server.

We do recommend adding the Connexus IP range to Trusted sites so SafeMail will be able to send to your computer. You can do this by click on the Trusted and Banned IPs link on the left hand side and entering the information as seen below. Click on OK to save your changes.

hr

SafeMail and Trend Micro

Open PC-cillin Internet Security Console and click on Personal Network & Firewall Controls.

Click on the Settings button and select Direct Internet Connection from the list. Click on Edit to modify this Profile.

Click on the Network Control tab at the top.

We wish to allow only the mail coming from Connexus SafeMail servers (203.12.22.1 – 203.12.22.254) on port 25. Click on add to create a new ‘allow’ rule configured as shown below and click on OK.

Now that we have allowed SafeMail to send us mail we wish to block other mail servers from sending us mail. Click on Add to create a new ‘deny’ rule configured as shown below and click on OK.

Your firewall rules are now setup. Click on OK and close the PC-cillin Internet Security Console.

hr

SafeMail and Microsoft Exchange 2000.

The following guide is an example of how to configure Microsoft Exchange 2000 to use Connexus SafeMail as a Smarthost.

Exchange 2000 has two options for routing outbound mail to an external SMTP mail server. If you are in a single-server, single organizational Exchange environment (small office/home office--SOHO), you can configure Exchange with a single update:

  • Start the Microsoft Management Console (MMC) Exchange System Manager snap-in (Start, Programs, Microsoft Exchange, System Manager).
  • Expand the organization and expand the server.
  • Expand the server's Protocols branch, then expand the SMTP branch.
  • Right-click Default SMTP Virtual Server, and click Properties.
  • Select the Delivery tab.
  • Click Advanced to bring up the Advanced Delivery dialog box.
  • In the Smart host field, enter mail.connexus.net.au
  • Click OK to exit all the dialog boxes.
  • Use the following statements to stop and restart the SMTP service:

    C:\> net stop smtpsvc
    C:\> net start smtpsvc

If you are in a multi-server, multi-organizational Exchange environment, you need to use the SMTP Connector:

  • Start the MMC Exchange System Manager snap-in (Start, Programs, Microsoft Exchange, System Manager).
  • Expand the organization, the routing group, and then the Connectors branch.
  • Right-click the Connectors branch, and select New, SMTP Connector.
  • On the General tab, provide a name for the connector (the external SMTP server's name would be useful), and select "Forward all mail through this connector to the following smart hosts."
  • Enter mail.connexus.net.au
  • Under Local bridgeheads, click Add and select a server in the Exchange organization.
  • Select the Address Space tab.
  • Click Add.
  • Select the SMTP address type.
  • Under E-mail domain, leave the default asterisk (*) and click OK.
  • Under Delivery Options, there are other connection options. If you are on a leased/DSL connection, use "Always run" for Connection Time because you'll always have a connection.
  • Click OK

After using either method, you should have external mail capability.