We are running Exchange 2003 and receiving a lot of NDR attacks. I would like to know if receiving a lot of these attacks have effect on the Exchanges performance. Does anyone have suggestions on how to stop these attacks from reaching the server? We have checked the settings and even ran a test to make sure we are not a relay, the results confirmed we are not a relay.
Example of one of many 7010 errors in Event Viewer: This is an SMTP protocol log for virtual server ID 1, connection #370. The client at "64.80.108.51" sent a "xexch50" command, and the SMTP server responded with "504 Need to authenticate first ". The full command sent was "xexch50 1904 2". This will probably cause the connection to fail.
|