SOLVED
Home

Mail flow in Hybrid w/Appliance

%3CLINGO-SUB%20id%3D%22lingo-sub-1122764%22%20slang%3D%22en-US%22%3EMail%20flow%20in%20Hybrid%20w%2FAppliance%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1122764%22%20slang%3D%22en-US%22%3E%3CP%3ECurrent%20we%20have%3A%3C%2FP%3E%3CP%3EInbound%3A%3CBR%20%2F%3EInternet%20--%26gt%3B%20MX%20MacAfee%20Appliance%20(Spam%20and%20Virus%20filtering)%20--%26gt%3B%20Exchange%202010%20--%26gt%3B%20Exchange%20Edge%20--%26gt%3B%20Office%20365%3C%2FP%3E%3CP%3EOutbound%20is%20the%20reverse.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20want%20to%20remove%20Exchange%202010%20servers%20and%20keep%20one%20Exchange%202016%20for%20mail%20object%20maintenance.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIdeally%2C%20we%20want%20the%20mail%20flow%20to%20change%20to%20this%3A%3C%2FP%3E%3CP%3EInbound%3A%3CBR%20%2F%3EInternet%20--%26gt%3B%20MX%20Mcafee%20Appliance%20(Spam%20and%20Virus%20filetering)%20--%26gt%3B%20Office%20365%3CBR%20%2F%3EOutbound%20is%20the%20reverse.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGoing%20thru%20the%20McAfee%20Appliance%20is%20mandatory%20by%20management.%20It%20lives%20in%20our%20DMZ.%20The%20MX%20records%20for%20the%20domain%20point%20here.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20can't%20find%20any%20documents%20that%20explain%20exactly%20how%20to%20set%20this%20up.%20Please%20point%20me%20in%20the%20right%20direction.%3C%2FP%3E%3CP%3EThanks%20in%20advance...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1122764%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1123972%22%20slang%3D%22en-US%22%3ERe%3A%20Mail%20flow%20in%20Hybrid%20w%2FAppliance%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1123972%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F232640%22%20target%3D%22_blank%22%3E%40Daniel%20Thompson%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20incoming%2C%20you%20would%20need%20to%20look%20at%20white-listing%20the%20IPs%20of%20the%20appliance%20in%20Exchange%20Online%20so%20it%20doesn't%20treat%20them%20as%20spam.%2C%20then%20point%20the%20appliance%20away%20from%20the%20current%20Exchange%202010%20and%20onto%20the%20MX%20record%20of%20your%20tenant.%20I'd%20also%20look%20to%20set%20up%20a%20connector%20to%20reject%20any%20email%20that%20doesn't%20come%20from%20your%20appliance.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20outbound%2C%20you'll%20want%20to%20set%20up%20a%20connector%20to%20route%20through%20all%20of%20the%20email%20to%20your%20appliance%20-%20something%20like%20from%20Office%20365%20to%20partner%20organisation.%20I'm%20not%20familiar%20with%20your%20particular%20appliance%2C%20but%20you%20might%20have%20to%20do%20some%20config%20on%20that%20so%20it%20expects%20emails%20to%20come%20from%20Office365%20rather%20than%20your%20old%20Exchange%20box.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.azure365pro.com%2Fconfiguring-mimecast-with-office-365%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.azure365pro.com%2Fconfiguring-mimecast-with-office-365%2F%3C%2FA%3E%26nbsp%3B-%20this%20may%20help.%20It's%20for%20Mimecast%20but%20once%20you%20get%20past%20all%20the%20directory%20sync%20stuff%20at%20the%20beginning%20it%20should%20be%20the%20same%20principle%20for%20mail%20routing%20with%20your%20own%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps%2C%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1126223%22%20slang%3D%22en-US%22%3ERe%3A%20Mail%20flow%20in%20Hybrid%20w%2FAppliance%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1126223%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F383653%22%20target%3D%22_blank%22%3E%40HidMov%3C%2FA%3Ethanks%20--%20this%20is%20the%20first%20reference%20i%20found%20to%20the%20connection%20filter.%20We'll%20give%20it%20a%20shot.%20I'll%20post%20the%20results%20when%20i%20have%20them.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Daniel Thompson
New Contributor

Current we have:

Inbound:
Internet --> MX MacAfee Appliance (Spam and Virus filtering) --> Exchange 2010 --> Exchange Edge --> Office 365

Outbound is the reverse.

 

We want to remove Exchange 2010 servers and keep one Exchange 2016 for mail object maintenance.

 

Ideally, we want the mail flow to change to this:

Inbound:
Internet --> MX Mcafee Appliance (Spam and Virus filetering) --> Office 365
Outbound is the reverse.

 

Going thru the McAfee Appliance is mandatory by management. It lives in our DMZ. The MX records for the domain point here.


I can't find any documents that explain exactly how to set this up. Please point me in the right direction.

Thanks in advance...

 

2 Replies
Highlighted
Solution

Hi @Daniel Thompson,

 

For incoming, you would need to look at white-listing the IPs of the appliance in Exchange Online so it doesn't treat them as spam., then point the appliance away from the current Exchange 2010 and onto the MX record of your tenant. I'd also look to set up a connector to reject any email that doesn't come from your appliance. 

 

For outbound, you'll want to set up a connector to route through all of the email to your appliance - something like from Office 365 to partner organisation. I'm not familiar with your particular appliance, but you might have to do some config on that so it expects emails to come from Office365 rather than your old Exchange box.

 

https://www.azure365pro.com/configuring-mimecast-with-office-365/ - this may help. It's for Mimecast but once you get past all the directory sync stuff at the beginning it should be the same principle for mail routing with your own device.

 

Hope this helps,

Mark

Highlighted

@HidMovthanks -- this is the first reference i found to the connection filter. We'll give it a shot. I'll post the results when i have them.

Related Conversations
The new Fluent design Mail Icon is here!
HotCakeX in Windows Insider Program on
1 Replies
SharePoint 2016 / sharepoint online
Share24x7 in SharePoint on
2 Replies
Office 365 Outlook accounts for Partners
opendesign in Microsoft 365 on
2 Replies
Ports
Rising Flight in Office 365 on
0 Replies