Enhanced filtering for connector and Transport rule

Ihka 21 Reputation points
2021-11-06T11:48:55.983+00:00

Hi,

my current mailflow is 3rd party Filter > Exchange 2019 > Exchange Edge > Exchange Online
Exchange Online will always see the IP of my Edge server as the sender and therefore SPF fails everytime. If I now use enhanced filtering for connectors and specify the IP addresses of my 3rd party filter as well as the IP of my Edge server, this should be resolved, because Exchange Online will see the actual sending IP, right?
But I have some transport rules which are based on the IP of my Edge server. These will then stop working? Is there any workaround?

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

Answer accepted by question author
Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
2021-11-06T12:32:07.707+00:00

Yes, in most cases you will need to disable any rules that depend on the IP of the Edge Server and come up with a different way to filter. What do these rules do now?

https://learn.microsoft.com/en-us/answers/questions/617573/enhanced-filtering-for-connector-and-transport-rul.html

146927-image.png

Was this answer helpful?


5 additional answers

Sort by: Most helpful
  1. Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
    2021-11-06T12:52:30.45+00:00

    Ok, seems like it would be easy to adjust these rules then... Instead of applying the disclaimer based on the Edge IP, apply based on the internal IP range or if the message is authenticated...

    Same with anti-spam, messages going through the hybrid connector should be considered authenticated since they wont lose their Exchange headers
    etc..

    Why not create some new rules now based on new criteria and apply to some test messages ( based on recipient or sender) and see how that looks?

    Was this answer helpful?

    0 comments No comments

  2. Ihka 21 Reputation points
    2021-11-06T12:49:30.39+00:00

    Actually, we are in hybrid mode with the majority of mailboxes already . But we have some domains pointed to EOP while the most are still pointing to the 3rd party filter. That is, why we have some of these rules currently.

    Was this answer helpful?

    0 comments No comments

  3. Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
    2021-11-06T12:45:26.567+00:00

    Yes, I would be ready to change some or all of those rules if you enable enhanced filtering. It sounds like you are not in hybrid Exchange Mode.

    Was this answer helpful?

    0 comments No comments

  4. Ihka 21 Reputation points
    2021-11-06T12:39:14.01+00:00

    I have rules set up to bypass anti spam based on the edge server IP. There are also other rules like adding an external disclaimer except if mails are originating from internal org. I also have some other rules which will reject emails in certain scenarios except from edge server IPs. So I think I cannot use enhanced filtering in an easy way because I would have to reconfigure all transport rules to match another attribute.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.