Forefront for Exchange 2010 - no mails in quarantine or incidents list

I have a client with Forefront 2010 installed on their exchange 2010 server. I see 45 messages that have been blocked as spam in the dashboard - 43 connection, 1 smtp and 1 content.
The client wants to know which messages are being blocked and which aren't, however when I open up the incidents and quarantine pages there is nothing there.
They have the antispam configuration set to stamp headers and continue for SCL5 to 9 and it seems to me that things should be in the quarantine.
I have all the logging options turned on and I've followed the other technet threads about this issue but none of those solutions seem to work on this machine.
If anyone has any ideas I would really appreciate it!

Hi,
Firstly, please make sure if you have enabled the anti-spam filtering engine of FPE. If yes, please refer to the blog below:
Exchange Content Filter settings are ignored
Besides, please make sure you have installed all the released hotfix rollups for FPE. Please also make sure that you have enabled "Enable content filtering incident logging" in Advanced Options of Global settings.
You can deliver quarantined items to specified recipients and set emial notification.
In addition, only an Administrator can access/manage the quarantine of FPE.
Please also ensure that you haven't configured FPE to automatically purge quarantined in a short time.
FPE content filter uses the Cloudmark™ Antispam engine to analyze each e-mail message and stamp it with a SCL.
When the setting 5 – 9 is selected, all messages with a rating of 5 or higher are treated as suspected spam. 
Messages with an SCL rating of -1 and 0 will be treated as non-spam. You have the option to Quarantine or Stamp header and continue processing mail with an SCL rating in the 5 – 9 range.
If the issue persists, you can adjust the SCL setting to a lower value to see if the issue persists.
The links below would be helpful to you:
Configuring content filtering
Configuring e-mail notifications
How to Manage Quarantined Files in Forefront Protection 2010 for Exchange Server
(FPE)
Best regards,
Susie

Similar Messages

  • Forefront for exchange 2010 - how long?

    Hi there.
    Read this article: http://blogs.technet.com/b/server-cloud/archive/2012/09/12/important-changes-to-forefront-product-roadmaps.aspx
    I would have additional question.
    Our company is MS Gold Partner and we need to renew our yearly license every year around AUGUST.
    We are thinking about changing our SPAM filter external gateway with exchange edge, but as we can see from that article, you Will be unable to renew it license after December 2015.
    I know that Microsoft offers online Forefront protection but that is not option in our case because of data sensitivity.We need an answer how long we Will be able to get updates regarding forefront for exchange 2010 and be licensed ok?
    I guess after 2015 december Forefront Exchange 2010 Will no longer recieve spam updates thru Windows update, right?
    And also engines Will not be updated after that date?
    Is this the correct view and understanding?
    with best regards
    bostjanc

    Hi Bostjanc,
    >>how long we Will be able to get updates regarding forefront for exchange 2010 and be licensed ok?
    I think you must have seen the information below in that blog.
    For current customers, Microsoft will continue to support the subscription through Dec.31, 2015. If customer subcriptions expire before Dec.31, 2015, and annot be renewed because the product is no longer offered, these products will continue to be supported
    through that date in order to provided with customers sufficient time to move to alternative solutions.
    You could also check the following blog.
    License extension for End-of-Life Antigen/Forefront products
    Note: Microsoft provides third-party contact information
    to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
    If the information above still cannot resolve your questions, please contact Microsoft to get definitive answers.
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Uninstall Forefront for Exchange 2010

    I have acquired another spam filter appliance that will used instead of Forefront for Exchange 2010.
    How do I uninstall Forefront for Exchange 2010 without any issues while still using Exchange 2010.
    Basically the email will go through the email appliance filter then to Exchange. I want to deactivate or uninstall Forefront for Exchange with impacting my email services. Is it as simple as just uninstalling it?

    Hi,
    About uninstalling Forefront for Exchange 2010, you could check the following article.
    If spam filtering was enabled, the configurations in the corresponding antispam settings in Microsoft Exchange that were leveraged by FPE will be retained by their Exchange antispam counterparts after FPE is uninstalled. These settings include: Connection
    Filtering, Sender ID Filtering, Sender Filtering, and Reciepient Filtering. To change these configuration settings you will need to modify them through the Exchange management console.
    Uninstalling Forefront Protection 2010 for Exchange Server
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • How to test if Spam protection with Forefront for Exchange 2010 works

    Hi there.
    Installed forefront for exchange 2010 on Exchange Edge server.
    We have tested virus protection with creating EICAR, but the question is, is there a way to check if SPAM Works fine, and how to?
    with best regards
    bostjanc

    Hi bostjanc,
    Since this is an issue on the Forefront side, I suggest ask Forefront Forum for help so that you can get more professional suggestions. For your convenience:
    https://social.technet.microsoft.com/Forums/forefront/en-US/home?forum=FOPE
    However, based on my knowledge, use the EICAR antivirus test file is the only built-in method to check whether the Anti-Spam configured correctly.
    You can try to send some test spams to your Exchange server for testing, even if this is a stupid method : )
    Thanks
    Mavis Huang
    TechNet Community Support

  • Mails blocked in queue the moment forefront for exchange 2010 started

    Hi,
    We have newly installed Forfront protection 2010 for Exchange 2010 installed in our exchange 2010 Edge Server.
    Mails got struck in the Queue immediatly after the forefront installations.
    Mailflow works properly one we unhook the forefront from Exchange.
    need to enable the forefront. Got struck in these. How to proceed up further.
    Thanks,
    Pradeep

    Hi,
    Please compare your configuration with the following blog or video. These might help.
    http://araihan.wordpress.com/2010/03/15/forefront-protection-2010-how-to-install-and-configure-forefront-protection-2010-for-exchange-server-2010step-by-step/
    http://www.youtube.com/watch?v=b2BgTmeXwUs
    (Note: Microsoft provides third-party contact information to help you find technical support. This contact
    information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.)
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Forefront for exchange 2010 setup wizard preinstall update request

    I'm trying to install FPE, but even before I install and after the extraction of the files im getting the following error message on both my CAS servers.
    I have the following roles installed on this Client Access Server im using for the initial install of Forefront.
    Do I need to install active directory domain services before I continue.

    Hi,
    Firstly, please refer to the similar thread below:
    FSEMachinePrep.exe
    fails saying Server Unavailable
    Based on my research,
    Microsoft Forefront Protection 2010 for Exchange Server (FPE) can be deployed on Exchange Edge Transport, Hub Transport, Mailbox server, or combined
    Hub/Mailbox roles.
    Exchange 2010 requires Active Directory to be in place except for the Exchange 2010 Edge role (for DMZ) which can be deployed in a workgroup with Active Directory Lightweight
    Directory Services. Both Exchange (Mailbox, HUB and CAS role) and therefore FPE requires an Active Directory on site.
    Did you set up a domain environment for exchange server? If yes, please check the group membership of the user and make sure that it is a member of the Organization
    Management role group. In addition, please also make sure that you can connect to the primary domain controller on the CAS servers.
    More information:
    Microsoft Exchange Server 2010: Exchange Server and Active Directory
    Best regards,
    Susie

  • Forefront for Exchange 2010 not working

    Hello:
    It said my license expired, but I renewed it with the MSDN number. For some reason one of our users continues to get spammed everyday, multiple times. I blocked the IP, but it did not help.
    Return-Path: [email protected]
    X-MS-Exchange-Organization-PRD: waywayblog.eu
    X-MS-Exchange-Organization-SenderIdResult: Pass
    Received-SPF: Pass (mydomain.com: domain of
    [email protected] designates 64.120.156.126 as permitted sender)
    receiver=mydomain.com; client-ip=64.120.156.126;
    -MS-Exchange-Organization-AuthSource: mydomain.com
    X-MS-Exchange-Organization-AuthAs: Anonymous
    X-MS-Exchange-Organization-Antispam-Report: MessageSecurityAntispamBypass
    TEK

    no they are all different, but one users is being flooded with them.
    From: Satellite Internet Provider [mailto:[email protected]]
    Cant read our Advertisement at all?
    Please browse here.
    Faster Internet Via
    Satellite
    TEK

  • Forefront protection for exchange 2010 - updates?

    Installed Exchange EDGE server with Forefront Protection for Exchange 2010.
    Installed hotfix update rollup 4 for forefront (I think it's the latest because I haven't found any newer).
    We have basically left everything on default in forefront, and if we take a look on dashboard in gui we see this error message:
    not all the antimalware engines selected in the forefront adminstration console for scanning have been enabled for updates.
    where should we take a look whats not being updated. Please a little help.
    with best regards,
    bostjanc

    Hi.
    Meanwhile I have also found information that it has been retired
    https://social.technet.microsoft.com/Forums/forefront/en-US/400fa485-edc9-499f-8294-c196496437d8/not-all-of-the-antimalware-engines-enabled-for-updates-successfully-updated-at-the-last-attempt?forum=FSENext
    bostjanc

  • Support Forefront Protection 2010 for Exchange 2010 SP3

    Hi
    I have a simple question: Is there a full support of FPE 2010 (Version 11.0.727.0) for Exchange 2010 SP3 (and Rollup Updates)?
    Thomas

    Hi,
    It seems that FPE 2010 for exchange 2010 SP3 is supported and you need to install the Rollup 4. For more detailed information, please refer to the link below:
    Hotfix Rollup 4 for Microsoft Forefront Protection for Exchange
    Updates for Microsoft Forefront and Related Technologies
    Hope this helps!
    Susie

  • Anti-spam Forefront for exchange

    Hello,
    I am having an issue with the anti-spam. I have a 2010 exchange and forefront for exchange version 11.0.713.0. We have been just using filter lists to identify spam and then send them to a junk-mail box. I was looking through he Forefront settings and enabled
    the anti-spam and all I would get is a loading bar then eventually it will error out and close. I was able to disable it via command line but now my filter lists are not stopping the spam anymore. I just need one of the methods to work the users are getting
    a lot more spam since all this. Any help would be greatly appreciated.

     I was looking through he Forefront settings and enabled the anti-spam and all I would get is a loading bar then eventually it will error out and close.
    Hi,
    What's the error you encountered? Could you please upload a screenshot?
    Any changes that you make to the antispam settings with the user interface will not work unless antispam functionality is enabled successfully.
    Have you tried to use command line to enable spam filtering?
    http://technet.microsoft.com/en-us/library/dd639377.aspx
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Configuration for LDAP IP Address and Port for Exchange 2010

    Let's say Exchange 2010 is installed on a computer that is joined to a domain. However, I would like to redirect LDAP authentication to another IP address and another port like how sharepoint implement it below
    http://sharepoint.stackexchange.com/questions/33540/ldap-authentication-connection-string
    Is it possible to do the equivalent for Exchange 2010?
    Note: I would like to do this without installing any Edge Transport server or Microsoft Forefront TMG

    The question I would need to ask is "Why would you need to do this?"  I ask because Exchange requires an Active Directory account for authentication.  That account may have permissions from some other directory (as in a linked mailbox),
    but the account is used to find it.  For SharePoint, you can authenticate to other directories directly.

  • Disater Recovery for exchange 2010 plan in Cloud computing

    Hi
    We  are  using exchange 2010  for our messaging solutions.  Please find below our current setup.
    mainsite:  MBX Server ---  1no --> Hyper V host
                    Hub&Cas ----- 1No --> Hyper V Host
                    Edge  ---- 1NO --> Physical
    DR site : MBX,Hub&CAS  -- 1No --> Physical
                   Edge   --- 1no --> physical
    we enabled the DAG  for our Mail box server and its replicating  through a point to point link between our main site with DR site.
    Now we are interested to  enable   our DR (disaster recovery) in MS cloud.  Please let  me know the process  to go further .
    how will  the  DAG or DB  replicate to DR Site in cloud?. how its works?
    much appreciated if any body have  this setup .
    Best Regards
    Jagadeesan.S
    O
    Jags

    Hello,
    Kindly find the 3 types of plan for Exchange 2010 DR site. You can check all 3 plans and select as per your requirement.
    1. Rebuild an Entire Database Availability Group plan
    http://technet.microsoft.com/en-us/library/gg513521.aspx
    2. Site Resiliency in Exchange 2010
    http://www.msexchange.org/articles-tutorials/exchange-server-2010/management-administration/planning-deploying-testing-exchange-2010-site-resilient-solution-sized-medium-organization-part1.html
    3. Exchange 2010 Cross Site DAG Disaster Recovery: Data Center/AD Site failure Part 1
    http://msexchangeguru.com/2012/10/25/exchange-2010-dag-dr/
    Deepak Kotian. MCP, MCTS, MCITP Exchange 2010 Ent. Administrator

  • Forefront Protection Exchange 2010

    Does an Exchange Enterprise license cover you for Forefront Protection Exchange 2010?

    Hello,
    Only these Exchange license cover Forefront Protection for Exchange 2010 :
    Enterprise CAL with services
    Standard CAL + Enterprise with services
    Source (in french sorry):
    http://www.microsoft.com/exchange/2010/fr/fr/Licences.aspx
    Regards,
    Follow me on Twitter http://www.twitter.com/liontux | My Blog (French/English) :
    http://security.sakuranohana.fr/

  • Disater Recovery for exchange 2010 plan.

    Hi All,
    Happy New year 2014 ....
    we have running with exchange 2010 R1 with DAG enabled. we have below mentioned setup in our exchange server.
    Main site.
    Active directory server ( Primary DC, additional DC in our main site)  installed in Hyper V  host. installed exchange 2010 mail box role in another Hyper V host.  installed the CAS& Hub role in another virtual host and installed the Exchange
    edge role in another physical server.
    DR Site
    Active director server( ADC) installed in Hyper V host. installed the Exchange 2010 mailbox,Hub,Cas server role in a physical server. installed the Edge Server in another physical server.
    At present we have enabled the failover DAG  for both our Mail box servers and its working perfectly when the primay mail box server down. we have run some commands to transfer all my exchange 2010  to point through our DR Site. so its take
    some of the minutes of down time happened in our mail flow.  we are planning to avoid that downtime. we  are find for the solutions like  if the primary site down  the DR will need to automatically up. it will be appreciate that any
    one  provide your suggestion to achieve this without affecting the  our current setup.
    Jags

    Hello,
    Kindly find the 3 types of plan for Exchange 2010 DR site. You can check all 3 plans and select as per your requirement.
    1. Rebuild an Entire Database Availability Group plan
    http://technet.microsoft.com/en-us/library/gg513521.aspx
    2. Site Resiliency in Exchange 2010
    http://www.msexchange.org/articles-tutorials/exchange-server-2010/management-administration/planning-deploying-testing-exchange-2010-site-resilient-solution-sized-medium-organization-part1.html
    3. Exchange 2010 Cross Site DAG Disaster Recovery: Data Center/AD Site failure Part 1
    http://msexchangeguru.com/2012/10/25/exchange-2010-dag-dr/
    Deepak Kotian. MCP, MCTS, MCITP Exchange 2010 Ent. Administrator

  • Exchange 2010 server (Mail,HUB and CAS) installation in new site.

    We are  planned to install Exchange 2010 servers(MAIL,HUB and CAS) server in new Active director site in existing exchange organization.
    Kindly share best practice link for exchange server installation in new site.

    The best practice for installing into a new Active Directory site is the same as installing into a new organization, except you don't need to prepare the organization or domains (unless you are also installing into a new domain that hasn't been prepared).
    Install the CAS then hub, then mailbox roles, or install a multi-role server, then define your CAS Array name and IP address, and set your CAS behind a load balancer (if needed). Add your external certificate to both the CAS and the load balancer (and the
    hub if you use TLS for mail transfer), and you should be golden.  Also, if you intend to proxy your CAS connections, here's a link that may help: 
    https://technet.microsoft.com/en-us/library/bb310763.aspx?f=255&MSPPError=-2147217396
    For completeness, here's a thread on the msexchange.org forums that specifically mentions adding Exchange into a second site: 
    http://forums.msexchange.org/New_Exchange_2010_at_another_Site/m_1800557445/tm.htm

Maybe you are looking for

  • Long text doesn't fit the window exactly

    Hi friends, in PO smartforms i have included the header text of PO. the problem is the long text doesn't fit to the window exactly i.e., when we enter the text in PO in the header a line can contain only 60 characters approximately where as in my sma

  • Down loaded Lion now my internet is not connecting

    My Mac keeps seaching for connectivity and sometimes finds it and other times doesn't.  This never happened with Leopard

  • How to delete variable from memory

    Hi, I need to delete specfic session variables from memory. How do I do this? What command? Thanks.

  • AA 7.0 unable to "Create PDF From Scanner..."

    I am unable to use Adobe Acrobat 7.0 to scan from my Lexmark X9575 multifunction scanner. The scanner shows up in the drop down; however, when i go to scan it says "the selected scanner was not found". HELP please :)

  • Turning off the drop down option in a ALV grid

    Hello, I have defined a ALV grid where I defining my field catalog manually. Here is an example of one field:   gs_fieldcat-fieldname = 'DZTERM'.   gs_fieldcat-ref_table = 'VBFHAPO'.   gs_fieldcat-coltext   = text-004.   gs_fieldcat-edit       = 'X'.