We recently started using an upstream host to scan our E-mail for spam/viruses and then deliver them to our mail server. We're currently using Exchange 2003 with an Astaro 220 acting as the SMTP proxy/gateway. I have the mail service's IP addresses defined in the Upstream hosts section on the Astaro and am only allowing traffic from the upstream host. I'm not sure this is the best way to set things up, however...
1. Since our mail provider is now scanning everything, I'd like to lessen the load on our firewall and not have it provide spam/av scanning. If I still want the Astaro to function as a mail proxy, is it best to just exclude the upstream host's IP addresses from all scanning?
2. Would it be better to just disable the SMTP processing on the Astaro and have E-mail flow directly to/from the Exchange server? An advantage of the Astaro SMTP is the TLS setup. TLS on Exchange seems a bit more cumbersome to configure, especially if you need to allow both TLS and non-TLS traffic.
Thoughts/suggestions/advice appreciated. Thanks.
This thread was automatically locked due to age.