Applies to: Exchange Server 2007 SP3, Exchange Server
2007 SP2, Exchange Server 2007 SP1
Topic Last Modified: 2009-06-29
The following Microsoft Exchange Server 2007 installation guide template can be used as a starting point for formally documenting your organization's server build procedures for Exchange 2007 servers with the Edge Transport server role installed.
Executive Summary
The purpose of this document is to explain the installation and configurations necessary to install the Exchange Server 2007 Edge Transport server role.
Business Justification
By having an installation guide, Contoso will be able to ensure standardization across the enterprise, reducing Total Cost of Ownership, and easing troubleshooting steps.
Scope
The scope of this document is limited to installation of an Exchange 2007 Edge Transport server for Contoso on the Windows Server 2003 Enterprise x64 Edition operating system platform.
Prerequisites
The operator should have working knowledge of Windows Server 2003 Enterprise x64 Edition concepts, Exchange Server 2007 concepts, the Exchange Management Console and Exchange Management Shell, the command line, and various system utilities. This document does not elaborate on the details of any system utility except as necessary to complete the tasks within.
In addition, the operator should review the Planning for Edge Transport Servers topic in the Exchange 2007 Online Help before implementing the server role.
Assumptions
This document assumes that Windows Server 2003 Enterprise x64 Edition is installed per company baseline regulations which include the latest approved service pack and hotfixes. The current service pack level is Windows Server 2003 Service Pack 2 for x64 Editions.
It is also assumed that the following are installed:
- Windows Server 2003 Service Pack 2 32-bit Support
Tools are installed on the server as the tools are useful for
troubleshooting.
- Windows Server 2003 Resource Kit Tools are
installed on the server as the tools are useful for
troubleshooting.
This document assumes that forest and domain preparation steps have been performed per How to Prepare Active Directory and Domains topic in the Exchange 2007 Online Help.
This document assumes that both Exchange 2007 and Windows Server 2003 will be secured following the best practices found in:
- Exchange Server 2007: Security and
Protection
- Windows Server 2003: Windows Server 2003 Security Guide
Important: The procedures within this document should be followed sequentially. If changes are made out of sequence, unexpected results may occur.
This document also assumes that the host record for the Edge Transport server is generated within the internal forest's DNS so that the Hub Transport servers can locate the Edge Transport servers.
Server Configuration
The following media are required for this section.
- Windows Server 2003 Enterprise x64 Edition media
- Exchange 2007 Configuration DVD
Note: For instructions about how to build the Exchange Server 2007 Configuration DVD, see How to Create a Configuration DVD and Automation Files.
Additional Software Verification
- Verify that Remote Desktop is enabled.
- As an optional process, install Microsoft Network Monitor.
Network Interfaces Configuration
The Edge Transport server will use DNS for the following two types of lookups:
- MX record lookups for DNSEnabled Send Connectors (this can be
overridden on the connector).
- A record lookups to resolve Hub Transport servers for routing
mail into the organization (HOSTS file can be used instead).
- Log on to the server with an account that has at least local
administrative access.
- Click Start, Control Panel and right-click Network
Connections, and select Open.
- Locate the connection for the network(s) and rename it
appropriately.
- Right-click the network connection and select
Properties.
- Select Internet Protocol (TCP/IP) and click the
Properties button.
- Add or adjust the following items:
- Static IP Address, Subnet Mask, and
Gateway.
- DNS Server IP Addresses.
- Check the box to Append parent suffixes of the primary DNS
suffix.
- WINS IP Addresses (if using WINS).
- Static IP Address, Subnet Mask, and
Gateway.
DNS Suffix Configuration
Important: |
---|
Changing the DNS suffix will require uninstalling and reinstalling the Edge Transport server role, so be sure to set the DNS suffix properly before Edge Transport server installation. |
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
a DNS Suffix for the Edge Transport Server Role.
Drive Configuration
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Open the Disk Management MMC and format, rename, and
assign the appropriate Drive Letters so that the volumes and
DVD drive match the appropriate server configuration. At the very
least, there should be a D drive for the Exchange binaries and the
DVD drive should be configured as the Z drive. Refer to the
Database Log LUN Appendix at the end of this document for the
actual drive configuration that should be used.
Drive configuration
LUN Drive letter Usage 1
C
Operating system
2
D
Exchange binaries, tracking logs, databases
3
E
Exchange transaction logs
4
Z
DVD drive
Internet Explorer 7 Installation
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Insert the Exchange 2007 Configuration DVD.
- Browse to \IE7\ and double-click
IE7-install.bat.
- Click Yes for any Digital Signature not Found dialog
boxes that may appear.
Note: These dialog boxes will not appear in environments that have not deployed the Windows Security templates. - Wait for all file copies to complete and restart the
server.
Windows Server 2003 Post-SP2 Hotfix Installation
All hotfixes are installed through a batch file. For a complete list of hotfixes that are installed, see Contoso server build DVD hotfix list. A sample hotfix list can be seen at Server Build DVD - Sample Hotfix List.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access and was delegated
local Administrator access.
- Insert the Exchange 2007 Configuration DVD.
- Browse to \W2K3-PostSP2\ and double-click
W2K3-post-sp2.bat.
- Click Yes for any Digital Signature not Found dialog
boxes that may appear.
Note: These dialog boxes will not appear in environments that have not deployed the Windows Security templates. - Wait for all file copies to complete and restart the
server.
Domain Membership Configuration
Installing the Edge Transport server role into a domain is an optional step. Domain membership provides the ability to manage the server via group policy, control access, utilize Microsoft System Center Configuration Manager 2007, and utilize Microsoft System Center Operations Manager.
However, the Edge Transport server should not be installed in the internal forest for security purposes.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Click Start, right-click My Computer and select
Properties.
- Click the Computer Name tab.
- Click Change.
- Choose the Domain option button and enter the
appropriate Domain name.
- Enter the appropriate credentials.
- Click OK and OK.
- Click OK to close the System Properties.
- Restart the server.
Local Administrators Verification
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Verify (or add if not already there) that the following
accounts are members of the local administrators group on this
server.
Local administrators
Item Account Description Role 1
Domain Admins
Domain Administrative Global Group
Administrator
2
Root Domain\Exchange Organization Administrators
Exchange Administrators
Administrator
- Verify that your user account is a member of a group which is a
member of the local administrators group on the Windows Server 2003
server. If it is not, use an account that is a member of the local
administrators group before continuing.
Local Administrator Account Password Reset
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Click Start, right-click My Computer and select
Manage.
- Expand to Local Users and Groups\Users.
- Right-click Administrator and select Set
Password. Change the password so that it meets strong
complexity requirements.
- Optional: Right-click Administrator and select
Rename. Rename the account according to company
regulations.
Tools Installation
This section installs several useful tools that will aid administrators in Exchange administration and in troubleshooting support issues.
Note: |
---|
Debugging Tools for Windows will allow administrators to debug processes that are affecting service and determine root cause. For more information, see Debugging Tools for Windows - Overview. |
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Insert the Exchange 2007 Configuration DVD.
- Open a command prompt and browse to the \Support
folder.
- Run the following command where DVDROM-Drive is the DVD
drive: E2K7Toolsinstall.cmd DVDROM-Drive (ex:
E2K7Toolsinstall.cmd Z:).
- Right-click the c:\Tools folder and select
Properties.
- Click the Security tab.
- Click the Advanced button.
- Clear Inheritance and copy the permissions.
- Remove the Everyone (and if listed, the Authenticated
Users) security principal.
- Add the following groups, granting FULL CONTROL:
- SYSTEM
- The local Administrators group
- Creator Owner
- SYSTEM
Page File Modifications
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Click Start, right-click My Computer and select
Properties.
- Select the Advanced tab.
- Under Startup and Recovery, click the Settings
button.
- Under Write Debugging Information, change the memory
dump drop-down list to Kernel Memory Dump.
- Click OK.
- Under Write Debugging Information, change the memory
dump drop-down list to Kernel Memory Dump.
- Under Performance, click the Settings button.
- Click the Advanced tab.
- Under Virtual Memory, click the Change
button.
- On servers that have a dedicated page file drive, follow these
steps:
- For the C: drive, set the Initial Size (MB) value to a
minimum of 200 MB. (Windows requires between 150 MB and 2 GB of
page file space. The amount depends on server load and on the
amount of physical RAM that is available for page file space on the
boot volume when Windows is configured for a kernel memory dump.
Therefore, you may be required to increase the size.)
- For the C: drive, set Maximum Size (MB) to the value of
Initial Size.
- For the P: drive, type the result of one of the following
calculations in the Initial Size (MB) box:
- If the server has less than 8 GB of RAM, multiply the amount of RAM times 1.5.
- If the server has 8 GB of RAM or more, add the amount of RAM plus 10 MB.
- For the P: drive, set Maximum Size (MB) to the value of
Initial Size.
- Delete any other page files.
- Click OK.
- For the C: drive, set the Initial Size (MB) value to a
minimum of 200 MB. (Windows requires between 150 MB and 2 GB of
page file space. The amount depends on server load and on the
amount of physical RAM that is available for page file space on the
boot volume when Windows is configured for a kernel memory dump.
Therefore, you may be required to increase the size.)
- On servers that do not have a dedicated page file drive, follow
these steps:
- For the C: drive, type the result of one of the following
calculations in the Initial Size (MB) box:
- If the server has less than 8 GB of RAM, multiply the amount of RAM times 1.5.
- If the server has 8 GB of RAM or more, add the amount of RAM plus 10 MB.
- For the C: drive, set Maximum Size (MB) to the value of
Initial Size.
- Delete any other page files.
- Click OK.
- For the C: drive, type the result of one of the following
calculations in the Initial Size (MB) box:
- Click OK to close the System Properties dialog
box.
- Click No if you are prompted to restart the system.
Note: For more information on Page File recommendations, see the following articles: Configuring paging files for optimization and recovery in Windows Server 2003, in Windows 2000, and in Windows NT; How to determine the appropriate page file size for 64-bit versions of Windows Server 2003 or Windows XP; and Overview of memory dump file options for Windows Vista, Windows Server 2008, Windows Server 2003, Windows XP, and Windows 2000.
Drive Permissions
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Click Start and select My Computer.
- Right-click the D Drive and select
Properties.
- Click the Security tab.
- Select the Everyone group and then click
Remove.
- Select Users and then click Remove.
- Click Add and select the local server from
Locations.
- Grant the following rights as outlined in the following
table.
Drive permissions
Account Permissions Administrators
Full Control
SYSTEM
Full Control
Authenticated Users
Read and Execute, List, Read
CREATOR OWNER
Full Control
- Click the Advanced button.
- Select the CREATOR OWNER permission entry and then click
View/Edit.
- Select Subfolders and Files Only from the drop-down
list.
- Click OK two times.
- Click OK to close the drive properties.
- Repeat Steps 3-10 for each additional drive (other than the C
Drive).
Verification Steps
Organizational Unit Verification
This is an optional step and does not need to be followed for Edge Transport servers that are not deployed within a forest.
Submit a change request and have the computer object moved to the appropriate organizational unit (OU). If following the recommendations in the Exchange 2007 Security Guide, the OU will be \Member Servers\Exchange Backend Servers\Exchange EdgeTransport Servers.
Active Directory Site Verification
This is an optional step and does not need to be followed for Edge Transport servers that are not deployed within a forest.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Open a command prompt.
- Verify that the server is in the correct domain and Active
Directory site. At the command line run:
Copy Code NLTEST /server:%COMPUTERNAME% /dsgetsite
- The name of the Active Directory site to which the server
belongs will be displayed. If the server is not in the correct
Active Directory site, submit a change request to the appropriate
operations group and have the server moved to the appropriate
Active Directory site.
Domain Controller Diagnostics Verification
This is an optional step and does not need to be followed for Edge Transport servers that are not deployed within a forest.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Open a command prompt and change paths to the C drive.
- Run the following command:
Copy Code dcdiag /s:<Domain Controller> /f:c:\dcdiag.log
Note: Change <domain Controller> to a domain controller contained within the same Active Directory site as the Exchange server. - Review the output of C:\dcdiag.log file and verify that
there are no connectivity issues with the local domain
controller.
- Repeat steps 3 and 4 for each domain controller in the local
Active Directory site.
Note: Domain Controller Diagnostics (DCDiag) is a Windows support tool that tests network connectivity and DNS resolution for domain controllers. If the account being used does not have administrative rights, several tests under the Doing primary tests heading may not pass. These tests can be ignored if the connectivity tests pass. In addition, the log file may report that some service validation tests did not pass. These messages can be ignored if the services do not exist on the domain controller.
Network Diagnostics Verification
Network Diagnostics (NETDIAG) is a Windows support tool that tests network connectivity and DNS resolution for workstations and servers. Look for tests that failed and messages designated as "FATAL," and use this information to isolate network and connectivity problems.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Open a command prompt and change paths to the C drive.
- Run the following command: netdiag /Q /L.
- Review the output of C:\netdiag.log file and verify that there
are no network or connectivity issues with the Exchange Server.
Exchange Installation
The following CD media are required for this section:
- Microsoft Exchange 2007 DVD
- Exchange 2007 Configuration DVD
Exchange 2007 Prerequisites Installation
The following prerequisites will be installed through a batch file.
(This note should be updated to list the appropriate list of hotfixes for your environment.)
- Microsoft .NET Framework Version 2.0
Redistributable Package (x64).
- MMC 3.0 update is available for Windows Server 2003
and for Windows XP.
- .NET FW 2.0 Hotfix.
- Windows PowerShell 1.0 English Language
Installation Packages for Windows Server 2003 and for Windows
XP.
The installation steps are as follows:
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Insert the Exchange 2007 Configuration DVD.
- Browse to \E2K7-PreReqs\ and double-click
E2K7-prereqs.bat.
- Click Yes for any Digital Signature not Found dialog
boxes that may appear.
Note: These dialog boxes will not appear in environments that have not deployed the Windows Security templates. - Wait for all file copies to complete and restart the
server.
Exchange 2007 Installation
Though this document uses the command line method for installing the Exchange roles, the GUI can also be used. For more information about how to use the setup GUI to install an Exchange role, see the Exchange 2007 Online Help topic How to Perform a Custom Installation Using Exchange 2007.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access and was delegated the
Exchange Server Administrator role (or higher) if the server was
pre-created.
- Follow the procedure from the Exchange 2007 Online Help topic
How to Install
Exchange 2007 in Unattended Mode. For example, setup.com /r:MB
/t:d:\exchsrvr.
Exchange Server 2007 Post-SP1 Roll-up Installation
All hotfixes are installed through a batch file. For a complete list of hotfixes that are installed, see the Contoso server build DVD hotfix list.
A sample hotfix list can be seen at Server Build DVD - Sample Hotfix List.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access and was delegated
local Administrator access.
- Insert the Exchange 2007 Configuration DVD.
- Browse to \E2K7-PostSP1\ and double-click
E2K7-postsp1.bat.
- Click Yes for any Digital Signature not Found dialog
boxes that may appear.
Note: These dialog boxes will not appear in environments that have not deployed the Windows Security templates. - Wait for all file copies to complete and restart the
server.
Product Key Configuration
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access and was delegated the
Exchange Organization Administrator role.
- Follow the procedure outlined in the Exchange 2007 Online Help
topic How to
Enter the Product Key.
Security Configuration Wizard
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Install
the Security Configuration Wizard to install the Security
Configuration Wizard.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Register
Exchange Server Role SCW Extensions to register the Exchange
2007 Edge Transport Server SCW extension.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Create a
New Exchange Server Role SCW Policy to configure and apply the
policy.
System Performance Verification
By default, Exchange Server 2007 optimizes the server’s memory management for programs, which configures the server’s system cache as the default size.
- Connect to the server through Remote Desktop and log on with an
account that has local administrative access.
- Click Start, right-click My Computer and select
Properties.
- Select the Advanced tab.
- Under Performance, click the Settings button.
- Click the Advanced tab.
- Verify that the Processor Scheduling is set to
Background Services.
- Verify that the Memory Usage is set to System
Cache.
- Click the Advanced tab.
- Click OK.
Exchange Server Role Configuration
Clone Configuration
This is an optional step and need not be performed. If you would like to manually configure the settings (or if you need to as a result of the first Edge Transport server role being deployed), you can do so by reviewing the Appendix within this topic.
For more information about what information is and is not cloned, see the Exchange 2007 Online Help topic Using Edge Transport Server Cloned Configuration.
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
the Edge Transport Server Role by Using Cloned Configuration
Tasks to clone certain information from one Edge Transport
server to another.
- Verify that the cloned settings are applied by reviewing the
customized settings on the source server with this server. (The
Appendix within this topic may also be of help.)
EdgeSync Configuration
Before executing the EdgeSync configuration process, review the Exchange 2007 Online Help topic Preparing to Run the Microsoft Exchange EdgeSync Service.
- Connect to the server via Remote Desktop and log on with an
account that has local administrative permissions.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Export an
Edge Subscription File to export the necessary information to
enable synchronization to the Edge Transport Server from an Active
Directory Site within the Exchange organization.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Import
the Edge Subscription File to import the Edge Subscription file
into the Exchange organization and enable synchronization from the
Active Directory site to the Edge Transport server.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Force
EdgeSync Synchronization to force immediate
synchronization.
Message Size Limits Configuration
Before manipulating message size limits, review the Managing Message Size Limits topic from the Exchange 2007 Online Help.
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Click Start, All Programs, Microsoft Exchange Server
2007 and select Exchange Management Shell.
- Modify the maximum receive message size limit according to
company policy by running the following command where the value is
qualified in either KB or MB:
Copy Code Set-ReceiveConnector "Default Internal Receive Connector *" -MaxReceiveSize <MaxReceiveSize>
Domain Security Configuration
This section is optional and may be skipped.
Domain Security refers to the set of functionality in Exchange Server 2007 and Microsoft Office Outlook 2007 that provides a relatively low-cost alternative to S/MIME or other message-level security solutions. The purpose of the Domain Security feature set is to provide administrators a way to manage secured message paths over the Internet with business partners. After these secured message paths are configured, messages that have successfully travelled over the secured path from an authenticated sender are displayed to users as "Domain Secured" in the Outlook and Outlook Web Access interface.
For more information, see the Exchange 2007 Online Help topic Planning for Domain Security.
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Follow the procedures in the Exchange 2007 Online Help topic
Creating a Certificate or Certificate Request for TLSto
create and initialize a certificate for TLS use with SMTP.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
Mutual TLS for Domain Security to configure mutual TLS between
the mail systems.
Anti-Spam Update Configuration
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Follow the procedures in the Exchange 2007 Online Help topic
How to Configure
Anti-Spam Automatic Updates to allow for anti-spam automatic
updates.
Transaction Log Location
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Verify that the MSExchangeTransport service is stopped. If it
is not stopped, stop the service.
- Create the folder E:\Exchange\QueueLogs.
- Move the TRNxxxx.LOG and *.JRS files from <Exchange Install
Path>\TransportRoles\Data\Queue to the
E:\Exchange\QueueLogs.
- Navigate to <Exchange Install Path>\bin.
- Open the EdgeTransport.exe.config file in notepad and edit the
following entry:
Copy Code <add key="QueueDatabaseLoggingPath" value="E:\Exchange\QueueLogs" />
- Save the file.
Transport Logs Location
- Connect to an Exchange 2007 server via Remote Desktop and log
on with an account that has local administrative access and has
been delegated the Exchange Server Administrator role (or
higher).
- Verify that the MSExchangeTransport service is stopped.
If it is not stopped, stop the service.
- Create the E:\Exchange\Logs folder.
- Move the folders that reside in <Exchange Install
Path>\TransportRoles\Logs to the E:\Exchange\Logs
folder.
- Open the Exchange Management Shell and run the following
commands:
Copy Code Set-TransportServer <ServerName> -ConnectivityLogPath "E:\Exchange\Logs\Connectivity" -MessageTrackingLogPath "E:\Exchange\Logs\MessageTracking" -ReceiveProtocolLogPath "E:\Exchange\Logs\ProtocolLog\SmtpReceive" -SendProtocolLogPath "E:\Exchange\Logs\ProtocolLog\SmtpSend" -RoutingTableLogPath "E:\Exchange\Logs\Routing"
- Open a command prompt and start the transport service by
running the following command:
Copy Code command net start MSExchangeTransport
Temporary Storage Path
- Connect to an Exchange 2007 server via Remote Desktop, and
then log on to the server by using an account that has local
administrative access and has been delegated the Exchange Server
Administrator role (or higher).
- Verify that the MSExchangeTransport service is stopped.
If it is not stopped, stop the service.
- Move to the <Exchange Install Path>\bin
directory.
- Open the EdgeTransport.exe.config file in Notepad, and
then change the TemporaryStoragePath entry to point to the mail.que
drive. By default, this path is "C:\Program
Files\Microsoft\Exchange Server\TransportRoles\data\Temp."
Copy Code <add key="TemporaryStoragePath" value="<path of mail queue>" />
- Save the file.
ESE Performance Counter Activation
- Connect to the server via Remote Desktop, and then log on by
using an account that has local administrative access.
- Start Registry Editor.
- Locate the
HKEY_LOCAL_MACHINE\CurrentControlSet\Services\ESE\Performance
registry subkey.
- Right-click Performance, point to New, and then
click DWORD Value.
- Type Show Advanced Counters to name the new value.
- Double-click Show Advanced Counters.
- In the Value data box, type 1, and then click
OK.
- Exit Registry Editor.
Handoff Test
- Using test mailboxes located on the Internet, send sample
messages to various internal mailboxes and verify that mail is
successfully delivered.
- Send sample messages from internal mailboxes to various
Internet test mailboxes and verify that the mail is successfully
delivered.
- If Domain Security was implemented between two mail
organizations, test mail flow between the organizations and verify
that the message is listed as “Domain Secured” in the receiving
client.
- Review the event logs and tracking logs and ensure the Edge
Transport server is operating correctly.
Appendix
The following sections only need to be implemented if the following is true.
- This is the first Edge Transport server being deployed.
- The Edge Transport Cloned Configuration process is not
used.
Transport Server Configuration
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Click Start, All Programs, Microsoft Exchange Server
2007 and select Exchange Management Shell.
- Use the following table for information needed for the
commands.
Important: The values in the following table are example values, not recommended values. These values must be updated to reflect the actual values for your organization. Receive Connector Settings
Default value Example values MessageTrackingLogEnabled
True
True
MessageTrackingLogMaxAge
30.00:00:00
10.00:00:00
MessageTrackingLogMaxDirectorySize
250 MB
150 GB
MessageTrackingLogMaxFileSize
10 MB
10 MB
MessageTrackingLogSubjectLoggingEnabled
True
True
MaxPerDomainOutboundConnections
20
50
ConnectivityLogMaxAge
30.00:00:00
10.00:00:00
ConnectivityLogMaxDirectorySize
250 MB
150 GB
ConnectivityLogMaxFileSize
10 MB
10 MB
ReceiveProtocolLogMaxDirectorySize
250 MB
15 GB
ReceiveProtocolLogMaxFileSize
10 MB
10 MB
ReceiveProtocolLogMaxAge
30.00:00:00
10.00:00:00
SendProtocolLogMaxDirectorySize
250 MB
15 GB
SendProtocolLogMaxFileSize
10 MB
10 MB
SendProtocolLogMaxAge
30.00:00:00
10.00:00:00
ExternalDsnReportingAuthority
Server FQDN
<SMTP namespace>
- Modify the default settings by running the following
command:
Copy Code Set-TransportServer <ServerName> -MessageTrackingLogMaxAge <MaxAge> -MessageTrackingLogMaxDirectorySize <LogDirSize> -MessageTrackingLogMaxFileSize <LogFileSize> -ConnectivityLogMaxAge <MaxAge> -ConnectivityLogMaxDirectorySize <LogDirSize> -ConnectivityLogMaxFileSize <LogFileSize> -MessageTrackingLogSubjectLoggingEnabled <SubjectLogEnabled> -MaxPerDomainOutboundConnections <PerDomainOutboundConnections> -ReceiveProtocolLogMaxDirectorySize <ReceiveLogDirSize> -ReceiveProtocolLogMaxFileSize <ReceiveLogFileSize> -ReceiveProtocolLogMaxAge <ReceiveLogAge> -SendProtocolLogMaxDirectorySize <SendLogDirSize> -SendProtocolLogMaxFileSize <SendLogFileSize> -SendProtocolLogMaxAge <SendLogAge> -ExternalDsnReportingAuthority <SMTPNamespace>
- Modify the default settings by running the following
command:
Note: |
---|
For more information, see Set-TransportServer (RTM). |
Transport Agent Configuration
By default, all of these agents are enabled when the Edge Transport server role is installed. The steps below assume that each Transport Agent will be utilized as part of the message hygiene defense layer.
Review the Exchange 2007 Online Help topic Anti-Spam and Antivirus Functionality to understand the general strategy for configuring all anti-spam agents so that they work together efficiently for your organization.
- Connect to the server via Remote Desktop and log on with an
account that has local administrative access.
- Follow the procedures in the Exchange 2007 Online Help topic
How to Configure
Attachment Filtering to disable the filtering agent if it is
not desired, or to add or remove attachments from the default
list.
- To configure Connection Filtering, do the following:
- Follow the procedures from the Exchange 2007 Online Help topic
How to Add IP
Addresses to the IP Allow List and IP Block List to add entries
to the IP Allow or Deny lists.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
IP Allow List and IP Block List Providers to add block list
provider entries.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Add
Recipients to the Recipient Block List to add recipients to the
block list.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Add
Blocked Senders and Domains to Sender Filter to add senders to
the block list.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Add IP
Addresses to the IP Allow List and IP Block List to add entries
to the IP Allow or Deny lists.
- To configure Sender-ID Filtering, do the following:
- Follow the procedures from the Exchange 2007 Online Help topic
How to Exclude
Recipients and Sender Domains from Sender ID Filtering to
exclude certain entities from Sender-ID filtering.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
Sender ID Actions and configure the action that is taken by
Sender-ID filtering.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Exclude
Recipients and Sender Domains from Sender ID Filtering to
exclude certain entities from Sender-ID filtering.
- To configure Sender Reputation, do the following:
- Follow the procedures from the Exchange 2007 Online Help topic
How to Set the
Sender Reputation Level Block Threshold to set the threshold to
a different value.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure Outbound Access for Detection of Open Proxy
Servers for Sender Reputationto enable sender reputation to
traverse any firewalls that are between the Edge Transport server
and the Internet.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Set the
Sender Reputation Level Block Threshold to set the threshold to
a different value.
- To configure Content Filtering, do the following:
- Follow the procedures from the Exchange 2007 Online Help topic
How to Enable
and Configure the Spam Confidence Level Thresholds to adjust
the spam confidence levels for quarantine, reject, and delete
actions.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Specify
Recipient and Sender Exceptions for Content Filtering to
specify exceptions for content filtering.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
Allow or Block Phrases for Content Filtering to specify phrases
for content filtering.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Configure
the Rejection Response for Content Filtering to specify a
custom rejection response for content filtering.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Specify a
Spam Quarantine Mailbox to utilize the quarantine mailbox
feature.
- Follow the procedures from the Exchange 2007 Online Help topic
How to Enable
and Configure the Spam Confidence Level Thresholds to adjust
the spam confidence levels for quarantine, reject, and delete
actions.