﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>IT博客-山和云的彼端-随笔分类-Exchange</title><link>http://www.cnitblog.com/joyclear/category/7206.html</link><description /><language>zh-cn</language><lastBuildDate>Mon, 26 Sep 2011 05:53:41 GMT</lastBuildDate><pubDate>Mon, 26 Sep 2011 05:53:41 GMT</pubDate><ttl>60</ttl><item><title>AddReplicaToPFRecursive.ps1</title><link>http://www.cnitblog.com/joyclear/archive/2009/09/08/61306.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Tue, 08 Sep 2009 07:50:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/09/08/61306.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/61306.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/09/08/61306.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/61306.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/61306.html</trackback:ping><description><![CDATA[<p>Exchange 2007服务器公用文件夹做复制，通过SP1的管理界面可以一个个目录来设定，但是效率太低，如果公用文件夹多的话，就比较麻烦。</p> <p>从手册中查到AddReplicaToPFRecursive.ps1这个脚本可以批量添加服务器角色</p> <p>该命令的help</p> <p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/AddReplicaToPFRecursive.ps1_DE97/image_2.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/AddReplicaToPFRecursive.ps1_DE97/image_thumb.png" width="645" height="585"></a>  <p>但是这个命令有个bug，TopPublicFolder参数竟然不认空格。 <p>例如：某个目录的名称为 Office NewsGroup， 当在命令中里面输入 –TopPublicFolder “\Office NewsGroup”， 竟然不认。 <p>解决方法就是再套 ‘’符号， 也就是命令为 –TopPublicFolder <font color="#ff0000">“</font><font color="#0080ff">’ </font>\Office NewsGroup<font color="#0080ff">’</font><font color="#ff0000">”</font> .</p><img src ="http://www.cnitblog.com/joyclear/aggbug/61306.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-09-08 15:50 <a href="http://www.cnitblog.com/joyclear/archive/2009/09/08/61306.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007 CCR连续复制</title><link>http://www.cnitblog.com/joyclear/archive/2009/07/29/60438.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 29 Jul 2009 08:47:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/07/29/60438.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/60438.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/07/29/60438.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/60438.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/60438.html</trackback:ping><description><![CDATA[<p>这二天在重新做一下CCR的实验，突然想到之前有客户问，CCR的数据库日志是否可以选择心跳线传输，减少网络压力。</p> <p>在Exchange帮助文档中，关于群集网络有三种模式，如下描述，其中关于专用网络，数据库更新通讯使用此网络，这个<font color="#ff0000">数据库更新通讯</font>到底是指什么呢？是否就是日志传输？</p> <p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/Exchange2007CCR_EBCB/image_6.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/Exchange2007CCR_EBCB/image_thumb_2.png" width="781" height="142"></a> </p> <p>再继续查Help文档</p> <h5>冗余群集网络上的连续复制</h5> <p><font color="#ff0000">在 Microsoft Exchange Server 2007 的正式发布 (RTM) 版本中，CCR 环境中的所有事务日志文件复制和种子设定都发生在公用网络上</font>。此配置具有下列限制： <ol> <li>如果被动节点不可用达几个小时，可能会产生大量需要转输的日志。应该在被动节点可用时应尽可能快地移动这些日志。通过公用网络复制日志，日志的移动会与客户端通信争用资源。这将影响客户端通信并使重新同步变慢。</li> <li>在公用网络出现故障时，即使日志数据可用，故障转移也会丢失数据。</li> <li>使用孤立的网络进行日志通信时，可以为邮件数据提供安全性而无需使用加密，也不会引起与其相关的性能损失。</li> <li>在某些情况下，可能出现日志风暴。出现日志风暴时，系统会遇到不同寻常的高复制负担。如果日志数据必须在用于和客户端进行通信的网络上进行通信，可能会导致客户端资源不足。</li></ol> <p>所有这些问题并非都会以相同频率出现。但是，由于被动节点会因定期维护活动而脱机，第一个问题实际上肯定没几个月就会发生一次。 <p><font color="#ff0000">Exchange 2007 SP1 允许管理员在群集中创建一个或多个混合网络（例如，支持内部群集检测信号通信和客户端通信的群集网络）来进行日志传送</font>，最大限度地减少了上述问题的影响。Exchange 2007 SP1 还允许管理员指定用于种子设定的特定网络。 <p><em><font color="#ff0000">用于日志传送和种子设定的群集网络必须配置为混合网络</font>。混合网络是为群集（检测信号）和客户端访问通信而配置的任何群集网络。此外，在使用连续复制主机名配置的网络适配器上，<font color="#0000ff">管理员必须选中"高级 TCP/IP"<b></b>属性对话框上的"在 DNS 中注册此连接的地址"<b></b>复选框。</font>网络适配器使用的 DNS 服务器可以位于公用或专用网络上；但是，无论其位置如何，它必须可以被两个节点访问，以便可以进行主机名解析。</em> <p>支持在混合网络上进行日志文件复制是使用一个称为 <b>Enable-ContinuousReplicationHostName</b> 的新 cmdlet 来配置的。与此类似，关闭此功能使用 <b>Disable-ContinuousReplicationHostName</b> cmdlet 来完成。群集邮箱服务器位于 CCR 环境中之后，管理员可以在群集的两个节点上运行 <b>Enable-ContinuousReplicationHostName</b> 并指定其他 IP 地址和主机名，之后将在与每个节点相关的专用群集组中创建这些 IP 地址和主机名。执行此任务之后，Microsoft Exchange 复制服务将在成功配置和确认新网络正常运行之后立即开始使用新创建的网络进行日志复制。<font color="#ff0000">如果创建了多个新网络，Microsoft Exchange 复制服务将随机从中选择一个网络。如果指定的网络不可用，Microsoft Exchange 复制服务将自动开始使用其他复制网络，如果这些网络都不可用，它将在 5 分钟内开始使用公用网络进行日志传送。(</font>Microsoft Exchange 复制服务每 5 分钟进行一次网络检测。）当首选复制网络重新可用时，Microsoft Exchange 复制服务将自动恢复为使用该网络进行日志传送。 <p>那现在明了了，RTM中，日志传输是通过公用网络传输，SP1后，可以通过混合网络。因此如果我们如果要将日志文件通过心跳线传输，需要设置为混合网络。只是关于之前专用网络中的数据库更新通讯到底是指什么，还要再继续查下资料 <img src ="http://www.cnitblog.com/joyclear/aggbug/60438.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-07-29 16:47 <a href="http://www.cnitblog.com/joyclear/archive/2009/07/29/60438.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>RPC over Http保存用户名和密码</title><link>http://www.cnitblog.com/joyclear/archive/2009/07/02/59776.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Thu, 02 Jul 2009 04:45:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/07/02/59776.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/59776.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/07/02/59776.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/59776.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/59776.html</trackback:ping><description><![CDATA[<p>您的描述中，我理解到您想实现每次开启rpc over http Outlook客户端时，不用手动输入用户名和密码。<br>如果我理解错了，请告诉我<br>根据我的经验，我想共享给您两种方法，您可以根据您的情况来决定使用那个方法：<br>方法一:<br>=======<br>这种方法主要是将rpc over http用户的密码存储下来，这样以后每次开启rpc over http Outlook客户端时，就不用手动输入用户名和密码了。<br>具体步骤如下：<br>在rpc over http 客户端做一下步骤：<br>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 打开 控制面板，双击 Mail<br>2.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 打开对应邮箱帐户的属性，然后点击 More Settings<br>3.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 切换到 Security 选项卡，确保Always Prompt for logon <br>credentials没有启用. <br>4.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 点击 开始, 点击 运行. 输入下面的命令然后点击 确定<br>control keymgr.dll<br>5.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 在“Stored user names and passwords” 窗口内, 点击 Add.<br>6.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 然后添加Exchange RPC server 名字, 输入 用户名和密码<br>然后点击 OK<br>7.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 重启电脑<br>测试一下是否工作。<br>方法二: <br>=======<br>为rpc over http启用 NTLM authentication. 这种方法要求很苛刻：<br>1. Exchange RPC server 必须启用NTLM authentication <br>2. rpc over http 客户端Windows系统登陆用户和邮箱用户用的是同一个账号和密码<br>3. Exchange RPC server 和rpc over http 客户单之间如果有防火墙，防火墙必须支持NTLM authentication通过.<br>注释：根据我的经验, 大多数的防火墙都不支持NTLM authentication通过. <p>马海宾 （Jason Ma）<br>MCSE <img src ="http://www.cnitblog.com/joyclear/aggbug/59776.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-07-02 12:45 <a href="http://www.cnitblog.com/joyclear/archive/2009/07/02/59776.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>针对一些用户的特殊要求</title><link>http://www.cnitblog.com/joyclear/archive/2009/06/26/59665.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 26 Jun 2009 09:23:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/06/26/59665.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/59665.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/06/26/59665.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/59665.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/59665.html</trackback:ping><description><![CDATA[<p>根据您的描述，我对这个问题的理解是：您想限制一些用户的邮件功能。如果我的理解有误，请告诉我。<br>下面我将一一为您解答：<br>1．不能访问全球地址簿<br>您可以在命令行管理程序中运行下列命令来禁止某特定用户访问全球地址簿：<br>Get-GlobalAddressList "Default Global Address List" | Add-ADPermission -User "&lt;用户名&gt;" -AccessRights GenericRead -ExtendedRights Open-Address-Book -Deny:$True<br>注：请将&lt;用户名&gt;替换成您想禁止的用户帐号。<br>这样的话，该用户就无法在Outlook内打开并查看默认全球地址簿了。但是，若该用户以前登陆过他的邮箱的话，在他的电脑上可能会存有脱机地址簿。这样的话，除非他新建一个Outlook配置文件，不然的话他还是能够看到以前的默认全球地址簿（只不过无法看到最新的）。</p> <p>根据您的进一步要求，我又做了一些研究并且经过测试后，得出下面的方法来应用到多个用户。<br>1．首先，假设这些用户都在同一个名叫MVP的组织单元(OU)下。<br>2．我们先运行下面这个命令：<br>Get-GlobalAddressList "Default Global Address List" |fl<br>在得到的结果中，记下它的DistinguishedName。类似如下：<br>CN=Default Global Address List,CN=All Global Address Lists,CN=Address Lists Container,CN=&lt;OrganizationName&gt;,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=contoso,DC=com<br>3. 接着运行：<br>$gal = "CN=Default Global Address List,CN=All Global Address Lists,CN=Address Lists Container,CN=&lt;OrganizationName&gt;,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=contoso,DC=com"<br>即用$gal表示前面得到的这个名字。<br>4．最后运行：<br>Get-User –OrganizationalUnit MVP | Foreach { Add-ADPermission –Identity &amp;gal –User $_.Name –AccessRights GenericRead –ExtendedRights Open-Address-Book –Deny:$True }<br>注：简单解释下这条命令，先是用Get-User来get所有在MVP这个组织单元下的用户，然后对每个用户分别执行下Add-ADPermission的命令从而禁止MVP下的所有用户访问GAL。  <p><br>2．不能访问公用文件夹<br>如要禁止用户访问公用文件夹，我们可以先用Administrator账号登陆Outlook然后右键点击一个公用文件夹，选择“更改共享权限”，然后再添加指定账户并且将其权限等级设为“无”。然而这样的操作需要在每一个顶层文件夹上都执行一遍。<br>考虑到您的环境中公用文件夹数量可能较大，因此，我又想到了另外一种方法。<br>您可以在命令行管理程序中运行下列命令：<br>Get-PublicFolder –recurse | Add-PublicFolderClientPermission –AccessRights None –User &lt;用户名&gt;</p> <p>正是因为考虑到不去影响outlook 2003及以前版本的使用，我没有建议直接在Public Folder Hierarchy上将用户的访问公用文件夹权限直接去掉。因为，Outlook 2003及以前版本的用户依赖于公用文件夹来获取一些重要信息（例如：脱机地址簿，忙/闲信息等存在系统文件夹内的信息）。<br>因此，我们只能在非系统的公用文件夹上对用户一一限制权限，这样的话是不会影响到脱机地址簿等信息的。<br>至于同时禁止一组用户访问所有非系统的公用文件夹，经我测试，可以在我之前提供的方法上稍作改进：<br>1．首先，建立一个启用邮件的分发组<br>打开Exchange管理控制台，收件人配置-&gt;通讯组，这里新建一个分发组（假设名叫usergroup）<br>双击打开该分发组，点击“成员”标签，将您需要限制的用户添加进去。<br>然后再在命令行管理程序中运行：<br>Get-PublicFolder –recurse | Add-PublicFolderClientPermission –AccessRights None –User usergroup<br>注：这里最后的usergroup即刚才新建的分发组。<br>这样的话，所有该组内的成员都无法访问公用文件夹了，并且不影响到其它使用。 <p>黄 波<br>在线合作伙伴支持工程师<br>合作伙伴支持部<br>微软全球技术支持中心</p><img src ="http://www.cnitblog.com/joyclear/aggbug/59665.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-06-26 17:23 <a href="http://www.cnitblog.com/joyclear/archive/2009/06/26/59665.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>后知后觉</title><link>http://www.cnitblog.com/joyclear/archive/2009/06/05/59070.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 05 Jun 2009 04:14:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/06/05/59070.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/59070.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/06/05/59070.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/59070.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/59070.html</trackback:ping><description><![CDATA[<p>今天才发现Exchange 2007取消OMA功能了，这个功能以前一直不注意，因为手机是Windows mobile的，现在手机换了nokia塞班，倒想起这个功能了，结果竟然取消了…</p><img src ="http://www.cnitblog.com/joyclear/aggbug/59070.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-06-05 12:14 <a href="http://www.cnitblog.com/joyclear/archive/2009/06/05/59070.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>关于收到自己给自己发的垃圾邮件这个问题，Exchange 2007 edge解决</title><link>http://www.cnitblog.com/joyclear/archive/2009/05/13/57203.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 13 May 2009 07:58:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/05/13/57203.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/57203.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/05/13/57203.html#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/57203.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/57203.html</trackback:ping><description><![CDATA[<p>关于收到自己给自己发的垃圾邮件这个问题，我们可以使用以下方法来阻止这些邮件：</p>
<p><br>1. 打开边缘服务器上adam ADSIEDIT。（开始-&gt;运行-&gt;输入ADSIEDIT.msc）,<font color=#ff0000>连接端口要设定为50389</font>，默认是389，这个让我查了半天<br>2. 浏览到Configuration-&gt;Services-&gt;Microsoft Exchange-&gt;First Organization-&gt;Adminstrative Groups-&gt;Exchange Administrative Group -&gt;Servers-&gt;server_name-(<font color=#ff0000>边缘服务器</font>)&gt;Protocols-&gt;SMTP Receive Connector。<br>3. 在右边点击Default接受连接器，右击打开属性。<br>4. 点击Security选项卡，选择Anonymous Logon。<br>5. 在权限列表中的Accept Authoritative Domain Sender，勾选Deny。<br>6. 重启Transport服务。<br>这样的话，凡是发件人是自己域的信都不可以从SMTP发过来。</p>
<p>参考</p>
<p><a href="http://technet.microsoft.com/en-us/library/cc779052(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc779052(WS.10).aspx</a></p>
<p>&nbsp;</p>
<p>更正，经过测试边缘服务器ADAM adsiedit没有安全选项卡， 需要通过下列命令设定。</p>
<p>Remove-ADPermission &#8211;Identity "Default Internal Receive Connector EXEDGE" -User "NT AUTHORITY\ANONYMOUS LOGON" &#8211;ExtendedRights ms-Exch-SMTP-Accept-Authoritative-Domain-Sender<br>或者：<br>Add-ADPermission &#8211;Identity "Default Internal Receive Connector EXEDGE" -User "NT AUTHORITY\ANONYMOUS LOGON" &#8211;ExtendedRights ms-Exch-SMTP-Accept-Authoritative-Domain-Sender -Deny</p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/57203.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-05-13 15:58 <a href="http://www.cnitblog.com/joyclear/archive/2009/05/13/57203.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007有edge存在的情况，外部用户如何使用pop3,smtp服务</title><link>http://www.cnitblog.com/joyclear/archive/2009/05/13/57201.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 13 May 2009 07:46:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/05/13/57201.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/57201.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/05/13/57201.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/57201.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/57201.html</trackback:ping><description><![CDATA[<p>根据您的描述，我对这个问题的理解是：您想知道在装有Edge服务器的情况下如何使用户使用POP、SMTP方式正常收发邮件。如果我的理解有误，请告诉我。<br>在Exchange 2007 Hub服务器上，预设有一个接收连接器“Client &lt;服务器名&gt;”(打开Exchange管理控制台-&gt;"服务器配置"-&gt;"集线器传输"-&gt;"接收连接器")。对比我们常用的使用25端口的“Default &lt;服务器名&gt;”，“Client &lt;服务器名&gt;”使用 <br>587端口从而避免了与Edge服务器的端口冲突。<br>因此，您只需要对公网发布587端口，启用Client &lt;服务器名&gt;并进行相应的配置，然后让POP3用户设置使用587端口来替代25端口进行发信。<br>下面这篇我们Exchange团队的blog中讲述了这种情形供您参考，抱歉只有英文版本：<br>Quick-Start Guide to Configuring POP3 and IMAP4 in Exchange 2007<br><a href="http://msexchangeteam.com/archive/2007/05/16/439093.aspx">http://msexchangeteam.com/archive/2007/05/16/439093.aspx</a> <p>&nbsp; <p>由于Edge是处在公司外部网络中的，因此POP3用户无法通过Edge经由DC来进行身份验证，而必须连接到HUB服务器上 <p>另外根据以前项目的经验，可以采用二个公网ip地址的方式。</p><img src ="http://www.cnitblog.com/joyclear/aggbug/57201.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-05-13 15:46 <a href="http://www.cnitblog.com/joyclear/archive/2009/05/13/57201.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Export-mailbox</title><link>http://www.cnitblog.com/joyclear/archive/2009/05/08/57010.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Thu, 07 May 2009 16:51:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/05/08/57010.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/57010.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/05/08/57010.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/57010.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/57010.html</trackback:ping><description><![CDATA[<blockquote>
<p>客户咨询在Exchange 2007中需要清除一封发送给所有用户的邮件。</p>
</blockquote>
<p>将命令发送给客户 get-mailbox | export-mailbox &#8211;subjectKeywords &#8220;<em>邮件主题 " &#8211;</em>targetmailbox <em>administrator</em> &#8211;targetfolder <em>export -</em>DeleteContent</p>
<blockquote>
<p>客户反映测试执行export-mailbox命令后，用户的所有邮件都导入到administrator邮箱了，没有按照主题来筛选。</p>
</blockquote>
<p>不可能啊,我这里测试，一切正常，从客户发过来的运行截图来看，也都正常，没有问题。</p>
<p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/Exportmailbox_BEE/image_2.png"><img title=image style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; DISPLAY: inline; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=416 alt=image src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/Exportmailbox_BEE/image_thumb.png" width=644 border=0></a> </p>
<p>再查询下2007help文档，在export-mailbox中发现有下面一段：</p>
<p><font color=#ff0000>如果您使用任何关键字参数，<strong>Export-Mailbox</strong> cmdlet 将首先导出所有的邮件</font>，包括转储程序中的邮件，然后搜索目标邮箱寻找符合关键字条件的邮件。源邮箱上转储程序中的邮件会转换为目标邮箱上"已删除邮件"文件夹中的常规邮件，并且也要按关键字进行搜索。<font color=#ff0000>然后，<strong>Export-Mailbox</strong> cmdlet 将删除目标邮箱中与关键字条件不匹配的邮件。</font>如果同时使用 <em>DeleteContent</em> 参数，则 <strong>Export-Mailbox</strong> 将删除源邮箱中与关键字条件匹配的邮件。
<blockquote>
<p>赶紧询问客户是不是执行测试命令时候使用ctrl+c中断过，果然是这个状况。这下问题原因找出来了。
<p>按照这样看来，Export-mailbox和以前exmerge的工作模式还是有所区别的，像今天这个客户的情况，如果用户邮件数量比较多的话，执行这个命令恐怕得要花不少时间了。</p>
</blockquote>
<img src ="http://www.cnitblog.com/joyclear/aggbug/57010.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-05-08 00:51 <a href="http://www.cnitblog.com/joyclear/archive/2009/05/08/57010.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>ISA2006发布Exchange 2007RPC over HTTP故障解决</title><link>http://www.cnitblog.com/joyclear/archive/2009/04/22/56615.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 22 Apr 2009 06:59:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/04/22/56615.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/56615.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/04/22/56615.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/56615.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/56615.html</trackback:ping><description><![CDATA[<p>ISA2006发布Exchange ROH, 因为之前已经发布好了OWA，所以按照发布ROH向导，一步步完成，结果测试，竟然不行。</p> <p>逐步来排错。</p> <p>首先怀疑可能是证书的地方配置的有些不正确，重新申请配置证书(之前的证书在subjectname上按照help的格式有点问题，建议不要设定subjectname,它会套用domainname的第一个值)</p> <p>New-ExchangeCertificate -GenerateRequest -Path c:\certrequest.req -SubjectName "cn=mail.contoso.msft" -DomainName mail.contoso.msft,servername,servername.contoso.msft,autodiscover.contoso.msft -PrivateKeyExportable $true</p> <p>mail.contoso.msft是外部访问域名，当前环境域名和SMTP域名一致</p> <p>复制certrequest文本中的内容</p> <p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/ISA2006Exchange2007RPCoverHTTP_FE5D/image_2.png"><img title="Certrequest" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="489" alt="Certrequest" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/ISA2006Exchange2007RPCoverHTTP_FE5D/image_thumb.png" width="546" border="0"></a> </p> <p>进入企业CA证书申请页面,申请证书--高级证书申请--使用 base64 编码的 CMC 或 PKCS #10 文件提交 一个证书申请，或使用 base64 编码的 PKCS #7 文件续订证书申请。</p> <p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/ISA2006Exchange2007RPCoverHTTP_FE5D/image_4.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="507" alt="image" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/ISA2006Exchange2007RPCoverHTTP_FE5D/image_thumb_1.png" width="574" border="0"></a> </p> <p>下载证书，Base64编码</p> <p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/ISA2006Exchange2007RPCoverHTTP_FE5D/image_6.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="228" alt="image" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/ISA2006Exchange2007RPCoverHTTP_FE5D/image_thumb_2.png" width="417" border="0"></a> </p> <p>导入证书</p> <p>Import-ExchangeCertificate -Path c:\certnew.cer</p> <p>启用服务</p><pre>Enable-ExchangeCertificate -Thumbprint  -Services "POP,IMAP,SMTP,IIS"</pre><pre>&nbsp;</pre><pre>证书重新配置好后，导入ISA，结果ROH测试仍然失败，先从内部测试ROH，DNS服务器里面添加mail.contoso.msft记录。</pre><pre>客户端配置好ROH连接后，能连到exchange,奇怪，难道还是ISA问题？Ctrl+右键点击outlook工具栏图标--连接状态，只有邮件是通过HTTPS方式的，</pre><pre>其他目录连接还是通过TCP/IP方式。重新调整客户端网络设置，去除DNS服务器，在Host文件里面添加一条mail.contoso.msft记录，这次不能再连接到Exchange.</pre><pre>看来，问题还是在Exchange上面</pre><pre>在网上找到了相关的资料，确实在Windows2008+Exchange2007环境上存在这样一个Bug, 因为DSproxy组件侦听6004端口但不支持IPv6，因此需要关闭IPv6.</pre><pre>Exchange 2007 sp1 rollup4据说已经修复这个问题，不过更新好rollup4后，问题依旧。</pre><pre>那就关闭IPv6吧</pre>
<p>1. 网卡属性中取消IPv6选项。(这个之前就已经关闭)
<p>2. HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters下建立32位Dword, DisabledComponents 0xFF
<p>3. 重启电脑
<p>如果CAS和MailBox在一台机器上，还需要关闭loopback interface的IPv6
<p>在host文件中，记录 :::1&nbsp;&nbsp;&nbsp; localhost 前添加注释符#
<p>添加 Ip&nbsp;&nbsp; hostanme记录
<p>添加 ip&nbsp;&nbsp;&nbsp; FQDN记录
<p>保存host文件
<p>&nbsp; <p>至此问题解决，外部能正常访问outlook anywhere<pre>&nbsp;</pre><pre>&nbsp;</pre><pre>&nbsp;</pre><pre>&nbsp;</pre><pre>&nbsp;</pre><img src ="http://www.cnitblog.com/joyclear/aggbug/56615.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-04-22 14:59 <a href="http://www.cnitblog.com/joyclear/archive/2009/04/22/56615.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007针对发件人过滤添加白名单</title><link>http://www.cnitblog.com/joyclear/archive/2009/04/21/56533.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Tue, 21 Apr 2009 04:10:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2009/04/21/56533.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/56533.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2009/04/21/56533.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/56533.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/56533.html</trackback:ping><description><![CDATA[<p>Exchange2007针对发件人或域名添加白名单，在边缘管理工具上找了一下竟然没发现，还是只能在命令行界面设置。</p> <p>通过Get-ContentFilterConfig命令可以看到里面有BypassedSenders和BypassedSenderDomains二个参数</p> <p><a href="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/Exchange2007_AB18/image_2.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="133" alt="image" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/WindowsLiveWriter/Exchange2007_AB18/image_thumb.png" width="390" border="0"></a> </p> <p>可以使用Set-ContentFilterConfig –BypassedSenders <a href="mailto:jiang.cr211@gmail.com">jiang.cr211@gmail.com</a></p> <p>或者Set-ContentFilterConfig –BypassedSenderDomains gmail.com</p> <p>&nbsp;</p> <p>参考：<a title="http://exchangepedia.com/blog/2007/01/exchange-2007-content-filter-whitelist.html" href="http://exchangepedia.com/blog/2007/01/exchange-2007-content-filter-whitelist.html">http://exchangepedia.com/blog/2007/01/exchange-2007-content-filter-whitelist.html</a></p><img src ="http://www.cnitblog.com/joyclear/aggbug/56533.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2009-04-21 12:10 <a href="http://www.cnitblog.com/joyclear/archive/2009/04/21/56533.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Eseutil和Isinteg</title><link>http://www.cnitblog.com/joyclear/archive/2008/12/08/52335.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 08 Dec 2008 06:41:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/12/08/52335.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/52335.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/12/08/52335.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/52335.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/52335.html</trackback:ping><description><![CDATA[<p><strong>Isinteg.exe</strong> （Information Store Integrity）<br>信息存储完整性检查程序 (Isinteg.exe) 在<span style="COLOR: red"><strong>应用程序级别</strong></span>查找并消除公用文件夹数据库和邮箱数据库中的错误。Isinteg 并非作为日常信息存储维护的一部分使用；提供该工具是为了帮助进行灾难恢复。<span style="COLOR: #0000ff"><strong>由于 Isinteg 工具在逻辑架构级别工作，所以它能够恢复 Exchange Server 数据库实用程序 (Eseutil.exe) 无法恢复的数据。</strong></span>这是因为在物理架构级别对 Eseutil 工具有效的数据在逻辑架构级别的语义可能是无效的。 </p>
<p><span style="COLOR: #ff0000"><strong>Isinteg 通常在运行 Eseutil 修复操作后使用</strong></span>。Isinteg 工具执行以下两项主要任务： </p>
<ul>
    <li>从脱机备份还原后修补信息存储。<br>
    <li>测试信息存储中的错误，并有选择地进行修复。</li>
</ul>
<p>Isinteg 可以在应用程序级别修复信息以及邮箱、文件夹、邮件和附件之间的关系。 </p>
<br><br><br>Common mistake... which i use to see on most of the customer environment who use to run hard repair... may be this could be causing... <br><br>When we run hard repair major 3 steps procedure <br>eseutil /p <br>eseutil /d <br>isinteg -fix <br><br>Once we do eseutil /p&nbsp; run eseutil /mh and confirm your database status&nbsp;should be&nbsp;clean shutdown.. <br>Then run eseutil /d and then run eseutil /mh and confirm the status... <br><br>Now&nbsp; it's a time to mount the database (where the major mistake happen) <br><span style="COLOR: #ff0000"><strong>Client use to forget that then need only keep the .edb and stm and rest of the files like log files, chk, temp etc need to moved out because those log file have old signature and our database will new signature. <br></strong></span><br>Second think before you mount the database make sure you check the option "this database can be overwritten with the previous version" <br><br>Then dismount the database and run isinteg -fix <br>
<img src ="http://www.cnitblog.com/joyclear/aggbug/52335.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-12-08 14:41 <a href="http://www.cnitblog.com/joyclear/archive/2008/12/08/52335.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange中的邮件直推(Push Mail)</title><link>http://www.cnitblog.com/joyclear/archive/2008/12/03/52180.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 03 Dec 2008 09:44:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/12/03/52180.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/52180.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/12/03/52180.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/52180.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/52180.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;Push Mail是BlackBerry提出的名词，在Exchange中其实叫ActiveSync(邮件直推)<br>&nbsp;&nbsp;&nbsp;邮件直推的设计宗旨是为了通过无线网络连接使移动设备保持最新状态。<br>&nbsp;&nbsp;&nbsp;最早引进邮件直推技术是Exchange 2003 SP2版本&nbsp;<br><br>&nbsp;&nbsp;&nbsp;要使用直推技术，需要如下条件的设备支持：<br>1.Windows Mobile 5.0和Messaging&nbsp;&amp; Security Feature Pack (MSFP)及更高版本的Mobile移动电话。<br>2.由ActiveSync许可兼容直推技术的移动设备。<br><br>Exchange 2003 SP2中，默认功能没有开启，在Exchange2007中，默认已经开启直推技术。<br><br><strong>直推技术的原理：</strong><br>支持直推技术的移动设备将向Exchahnge服务器发出<strong style="COLOR: red">长期的HTTPS</strong>请求。Exchange服务器监视用户邮箱的活动，并在有任何更改时向设备发送响应。设备向服务器发出同步请求。完成同步后，将生成新长期HTTPS请求，以便再次开始该过程。<br><img height=373 alt="" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/Pushmail1.gif" width=459 border=0><br><br>直推技术依赖与支持长期HTTPS请求的网络条件。如果移动设备的运营商网络或防火墙不支持长期的HTTPS请求，则会停止HTTPS请求。<br><br>同时在移动运营商防火墙还会有超时值的设定，这个值决定长期HTTPS请求的发送周期，直推技术会依据运营商的超时值，自动判定最佳的发送周期<br><br>
<img src ="http://www.cnitblog.com/joyclear/aggbug/52180.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-12-03 17:44 <a href="http://www.cnitblog.com/joyclear/archive/2008/12/03/52180.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>在Exchange 2007中删除所有Disconnected Mailbox</title><link>http://www.cnitblog.com/joyclear/archive/2008/12/03/52167.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 03 Dec 2008 04:37:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/12/03/52167.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/52167.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/12/03/52167.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/52167.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/52167.html</trackback:ping><description><![CDATA[从您的描述中，我理解到您想一次性永久删除所有的 Disconnected Mailbox<br><br>如果我理解错了，请告诉我<br><br>您可以尝试下面的方法：<br><br>a. 打开 Exchange Management Shell,<br><br>b. 运行下面的命令:<br><br>$store= Get-MailboxDatabase "&lt;server_name&gt;\&lt;Storage_Group_Name&gt;\&lt;Mailbox_Database_name&gt;"<br><br>注释：这条命令将Exchange的数据库文件赋给了变量&#8220;$store"&#8221;<br>请将"&lt;server_name&gt;\&lt;Storage_Group_Name&gt;\&lt;Mailbox_Database_name&gt;"替换为您环境中的真实名字。<br><br>c.&nbsp; 继续运行下面的命令：<br><br>Get-MailboxStatistics -database $store | where {$_.disconnectdate -ne $null} | <br>foreach {remove-mailbox -database $store -storemailboxidentity $_.mailboxguid}<br><br>注释：这条命令将会将这个&#8220;$store&#8221;中所有的Disconnected Mailbox删除掉<br>
<img src ="http://www.cnitblog.com/joyclear/aggbug/52167.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-12-03 12:37 <a href="http://www.cnitblog.com/joyclear/archive/2008/12/03/52167.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>MsExchchangeCluster 1013 及 Userenv 1054问题解决</title><link>http://www.cnitblog.com/joyclear/archive/2008/12/02/52162.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Tue, 02 Dec 2008 15:14:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/12/02/52162.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/52162.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/12/02/52162.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/52162.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/52162.html</trackback:ping><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 下午四点赶往陆家嘴，解决客户Exchange群集问题，问题倒不是很紧急，但是客户环境比较特殊，只能在非工作时间解决，看来今天又要加班咯～～～<br>1.客户邮件服务器是Exchange 2003 Cluster, 群集资源中Exchange HTTP Virtual Server Instance 100 资源不能启用，导致用户无法访问OWA页面。<br>在日志中有MSExchangeCluster 1013等报错信息<br>事件描述：<br>Event Type: Error<br>Event Source: MSExchangeCluster<br>Event Category: Services<br>Event ID: 1013<br>Date: 25/80/2005<br>Time: 9:16:44 AM<br>User: N/A<br>Computer: exchange1<br>Description:<br>Exchange HTTP Virtual Server Instance 100 (exchange1): Failed to get the<br>protocol IP address and port bindings from the metabase.<br><br>打开IIS，里面虚拟服务器是停用状态，因为用户是比较重要的生产环境，所以暂时没有做任何操作，开始检查日志，Cluster日志，应用程序日志，系统日志，然后查EventID,微软KB。 看起来IIS元数据损坏的可能性比较大。<br>突然从网上找到一篇BBS, 里面的问题和现在问题一样，里面提到了<span><strong style="COLOR: red">This problem can be caused by the HTTP Virtual Server not having an SSL port defined when we are requiring SSL.<br></strong>立刻检查IIS里面SSL端口定义，果然是空值。输入443, 应用设定。重新启用群集中HTTP资源，服务正常启动了。<br>OWA页面正常开启。hoho~~， 万幸，还好不是IIS元数据库问题，否则今天加班到几点还是问题，万恶的加班啊～～～，万恶的加班又没有加班费啊～～～～<br><br>2.问题提前解决，时间充裕，那就继续解决客户的其它问题，客户反应DC服务器上周期出现Userenv 1054错误，组策略无法下发。<br>事件描述：<br><span><span>Event Source: Userenv</span></span><span><br><span>Event Category: None</span><br><span>Event ID: 1054</span><br><span>Date: 3/12/2008</span><br><span>Time: 8:42:38 AM</span><br><span>User: NT AUTHORITY\SYSTEM</span><br><span>Computer: ServerName</span><br><span>Description:</span><br><span>Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted. <br></span>经过检查，不光DC上有，多台成员服务器上也有这个现象。<br>这个问题以前也多次见过，一直没有好好解决。<br>看了EventID，很多人都说这个问题和硬件有关。继续查找资料～～<br>功夫不负有心人啊，总算找到篇有用的资料，说明问题和AMD CPU有关，AMD有Fix程序可以解决。<br>打开服务器硬件属性，果然都是用的AMD的CPU，看来问题有眉目。<br>接下来的工作就交还给客户了，请他明天先联系下HP，看下HP的Case记录里面是否对这个错误有解决方案，如果确实是CPU的问题话，应该HP会碰到很多类似问题。<br></p>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span class=spnmessagetext><span lang=EN-US style="COLOR: midnightblue; FONT-FAMILY: 'Verdana','sans-serif'">Just thought I'd throw this in here. Spent a bunch of time researching this, finally decided to call MS. </span></span><span lang=EN-US style="COLOR: midnightblue; FONT-FAMILY: 'Verdana','sans-serif'"><br><br><span class=spnmessagetext>Event Source: Userenv</span><br><span class=spnmessagetext>Event Category: None</span><br><span class=spnmessagetext>Event ID: 1054</span><br><span class=spnmessagetext>Date: 3/12/2008</span><br><span class=spnmessagetext>Time: 8:42:38 AM</span><br><span class=spnmessagetext>User: NT AUTHORITY\SYSTEM</span><br><span class=spnmessagetext>Computer: ServerName</span><br><span class=spnmessagetext>Description:</span><br><span class=spnmessagetext>Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted. </span><br><span class=spnmessagetext>-------------------------------------------------------</span><br><span class=spnmessagetext>We were getting this on a bunch of new servers, all running Win2003 R2 64bit. It's also showing up on a number of XP machines. Finally decided to just open a ticket with MS. </span><br><br><span class=spnmessagetext>The problem is apparently a "slow link detection", which is of course abundantly obvious from the errors. Per MS, we did the following reghacks: </span><br><br><span class=spnmessagetext>Registry subkey: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System </span><br><span class=spnmessagetext>Value name: GroupPolicyMinTransferRate </span><br><span class=spnmessagetext>Value type: DWORD </span><br><span class=spnmessagetext>Value Data: 0 </span><br><br><span class=spnmessagetext>Registry subkey: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System </span><br><span class=spnmessagetext>Value name: GroupPolicyMinTransferRate </span><br><span class=spnmessagetext>Value type: DWORD </span><br><span class=spnmessagetext>Value Data: 0 </span><br><br><span class=spnmessagetext>Note: if the "System" key doesn't exist, please create it under HKCU\Software\Policies\Microsoft\Windows &amp; HKLM\Software\Policies\Microsoft\Windows first.</span><br><br><span class=spnmessagetext>From the MS tech support rep:</span><br><br><span class=spnmessagetext>"It is possible that certain firewall program (such as Windows Firewall) is installed on all your machines and configured to block the normal ICMP packets. Sometimes it may be also caused by some models of CPU.</span><br><br><span class=spnmessagetext>For example, there is a known bug with AMD Opteron Processor driver for Windows XP and Windows Server 2003 Version (x86 and x64 exe) <a href="http://1.3.2.16/"><u><font color=#0000ff>1.3.2.16</font></u></a>, which allows the system to automatically adjust the CPU speed, voltage and power combination that match the instantaneous user performance need. The slow link detection depends on the CPU clock to calculate the speed. However, it may fail when working along with AMD Opteron driver. Recently we have received many reports that this known bug in the AMD CPU driver often causes the group policy detection failure. AMD has provided a new version of driver to solve such similar problems. You can get this point from:</span><br><br></span><span class=spnmessagetext><span lang=EN-US><a href="http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_9033,00.html" target=_blank><span style="FONT-FAMILY: 'Verdana','sans-serif'"><u><font color=#0000ff>http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_9033,00.html</font></u></span></a></span></span><span class=spnmessagetext><span lang=EN-US style="COLOR: midnightblue; FONT-FAMILY: 'Verdana','sans-serif'">" </span></span><span lang=EN-US style="COLOR: midnightblue; FONT-FAMILY: 'Verdana','sans-serif'"><br><br><span class=spnmessagetext>All our new servers are 64-bit Opterons. We haven't upgraded the driver yet. </span></span></p>
<p><br><br></span></span>&nbsp;</p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/52162.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-12-02 23:14 <a href="http://www.cnitblog.com/joyclear/archive/2008/12/02/52162.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007 连续复制深入</title><link>http://www.cnitblog.com/joyclear/archive/2008/10/09/50002.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 08 Oct 2008 16:36:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/10/09/50002.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/50002.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/10/09/50002.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/50002.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/50002.html</trackback:ping><description><![CDATA[<p>参考自Exchange 2007 连续复制白皮书：<a href="http://technet.microsoft.com/zh-cn/library/cc535020(EXCHG.80).aspx">http://technet.microsoft.com/zh-cn/library/cc535020(EXCHG.80).aspx</a><br><br>一。在Exchange 2007 SP1中，有三种连续复制形式<br>LCR本地连续复制<br>CCR群集连续复制<br>SCR备用连续复制<br><br>二。在简单的环境中，连续复制运行下列步骤：<br>1. 通过对源数据库的一份拷贝播种建立目的数据库<br>2. 通过windows文件系统提示事件，监控源数据库日志目录准备复制的新日志文件<br>3. 复制新的日志文件到目的检验日志目录<br>4. 检验已复制的日志文件<br>5. 通过成功检验，移动已复制日志文件到存储组日志路径，重播日志文件到数据库<br><br><strong>三。复制组件<br></strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;二个关键的组件负责日志产生，日志传送，和日志重播。<br>&nbsp;<strong>Microsoft Exchange Information Store Service</strong><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;负责用户和应用程序请求服务，执行日志写入，和通过<strong>Extensible Storage Engine (ESE)</strong>更新数据库文件<br><br><strong>Microsoft Exchange Replication Service</strong><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;复制日志传送和重播日志<br><br><strong>A。Information Store Service功能<br></strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;下面的步骤当在数据库中发生数据检索，插入和更改时由ESE来执行<br>1. 在数据库上发生一个操作(用户发送一封新邮件)，数据库中需要更新的页面读取到ESE缓存中(假定这个页面之前在内存中不存在)，当日志缓冲区得到提示，开始记录中内存中发生的操作。<br>2. 数据库引擎记录发生的变化但是这些变化并不马上写入到数据库文件。相反的，这些变化保存在ESE缓存中，因为这些页面没有提交到数据库文件，所以称之为 dirty pages 。Version Store被用来追踪这些变化，因此确保隔离性和一致性得到维护<br>3. 当数据库页面有变化，日志缓冲区得到提醒去递交变更，处理结果记录到交易日志文件，这些操作有可能需要关闭当前Exx.log文件，重新创建一个新的日志文件(ESE也负责响应当一个日志文件达到最大容量(1MB)后，关闭文件然后重新产生一个新的日志文件)。<br>4. 最后dirty 数据库页面写入到磁盘上的数据库文件<br>5. 检查点向前<br><br><strong>B。Replication Service功能</strong><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;当连续复制功能启用，Exchange Replication Service负责侦测当前日志文件是否被ESE关闭，复制日志文件，检验和重播到副本数据库。这个服务默认安装在邮件服务器角色上。<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Replicaton Serice的执行文件是Microsoft.Exchange.Cluser.ReplayService.exe, 路径在exchange安装目录\bin 。Replication服务依赖于Exchange Active Directory Topology服务。<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Replication服务日志诊断<br>HKEY_L_M\System\CurrentControlSet\Services\MSExchange Repl\Diagnostics<br><font face="Courier New">Get-EventLogLevel -Identity "MSExchange Repl"</font> or <code>Set-EventLogLevel -Identity "MSExchange Repl" -Level High<br><br></code><strong>C。Replication服务组件</strong><br>&nbsp;&nbsp;&nbsp;<strong>LogCopier</strong>：负责复制已关闭日志文件，从源存储组到副本存储组。在Replication服务持续监视源存储组日志目录中这是一个异步操作。它通过订阅windows文件系统提示事件来监视。当事件提示Replication服务有一个新的文件存在，LogCopier将复制日志文件到目的服务器检验目录<br>&nbsp;&nbsp;<strong>&nbsp;LogInspector</strong>：负责检验日志文件是否正确，它通过基本的规则在检验目录中检验，如果一个日志文件发现是错误的或者不能被重播，Replication服务将重新复制日志文件。<br>&nbsp;&nbsp;&nbsp;<strong>LogReplayer</strong>：负责重播已检验文件到副本数据库<br>&nbsp;&nbsp;&nbsp;<strong>LogTruncater：</strong>负责删除已经成功重播到副本数据库的日志文件。这个组件非常重要，因为通常在全备或增量备份后，在检查点后的日志文件被删除，因为日志记录认为这些日志已经写入到数据库。当连续复制使用时，LogTruncator仅仅删除不需要恢复和重播的日志。任何在活动副本上没有被复制和重播到数据库副本的日志文件不会被在线备份清除。<br>&nbsp;&nbsp;&nbsp;<strong>Incremental Reseeder</strong>：负责确保当数据库恢复被执行时，或者当CCR环境中发生故障转移时，活动数据库和副本数据库不会分叉。<br>&nbsp;&nbsp;<strong>&nbsp;Seeder</strong>：负责创建存储组基本内容用于开始重播进程，Replication服务为新存储组，以及已存在的存储组(包含日志文件)执行自动播种。<br>&nbsp;&nbsp;&nbsp;<strong>Replay Manager：</strong>负责持续追踪所有的复制实例。基于存储组的在线状态，按需求创建和撤销复制实例。复制实例被特意设置为静态，因此，当一个复制实例配置更改，复制将应用新的配置重新启动。此外，当Replication服务被关闭，复制实例配置不会被保存。为此，每次Replication服务启动时，包含空复制实例列表，在启动期间，Replay Manager发现当前在线的存储组，创建"运行中的实例"列表。<br>&nbsp;&nbsp;&nbsp;Replay&nbsp;Manager周期性运行"配置更新"线程，扫描新的已配置复制实例。配置更新线程在LCR,CCR环境中每30秒运行一次，在SCR环境中，3分钟运行一次。它将在当前数据库状态上建立和破坏复制实例(取决于数据库是在线还是离线)。配置更新线程使用以下的算法：<br>1.从AD中读取实例配置<br>2.对比从AD中发现的配置，如果不匹配，实例进入重启队列<br>3.<br>4.停止在停止队列中的运行实例<br>5.启动在启动队列中的实例<br>因此，Replay Manager总是有动态的复制实例清单<br><br><strong>Replication Serivce配置信息<br></strong>每个启动LCR的存储组和存储都有msExchHasLocalCopy属性定义。Replication Service使用以下的算法去搜寻AD中的复制信息<br>1.在AD中使用计算机名称寻找Exchange Server对象，如果没有服务器对象，返回。<br>2.在找到的Exchange服务器上，枚举所有的存储组<br>&nbsp;&nbsp;&nbsp;1.每个msExchHasLocalCopy属性设定为真的存储组，检索系统文件，日志文件，和数据库文件的源目的路径。<br><br>在CCR环境中，Replication Service执行下列任务去检索集群的邮箱服务器配置<br>1.建立一条连接到集群数据库<br>2.判断哪个节点拥有集群邮箱服务器<br>3.枚举在源和目标节点上的所有存储组<br>&nbsp;&nbsp;&nbsp;A.系统文件，日志文件和数据库文件的源目的路径<br>&nbsp;&nbsp;&nbsp;B.返回存储组的最后拥有者<br>&nbsp;&nbsp;&nbsp;C.用于日志传送的网络共享空间<br>&nbsp;&nbsp;&nbsp;D.AutoDatabaseMountDial设定<br>&nbsp;&nbsp;&nbsp;E.ForcedDatabaseMountAfter设定<br>&nbsp;&nbsp;&nbsp;F.确定日志传送的网络路径<br>4.检验在源上的配置和目标上的一致<br><br>在SCR环境，复制服务使用msExchStandbyCopyMachines属性去判定哪个存储组启用复制，然后执行下列任务<br><br>&nbsp;&nbsp;&nbsp;<br><br><br><br><br></p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/50002.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-10-09 00:36 <a href="http://www.cnitblog.com/joyclear/archive/2008/10/09/50002.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2003中限制用户发送邮件</title><link>http://www.cnitblog.com/joyclear/archive/2008/09/26/49554.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 26 Sep 2008 07:18:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/09/26/49554.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/49554.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/09/26/49554.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/49554.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/49554.html</trackback:ping><description><![CDATA[目的需要限制用户发送邮件，但是能接受邮件<br><br><strong>限制发送到Internet</strong><br>限制员工发送邮件到组织外，可以在SMTP路由组连接器的拒绝来自下列发件人发送的邮件列表中添加想要禁止发信到Internet的用户。需要修改一下注册表才能生效。
<p align=left><font size=3>&nbsp;&nbsp;</font><font size=3>&nbsp;<font size=2>To resolve this issue:<br></font></p>
</font>
<p align=left>
<table class="list ol">
    <tbody>
        <tr>
            <td class=number><font size=2>1.</font></td>
            <td class=text><font size=2>Start Registry Editor (Regedt32.exe).</font></td>
        </tr>
        <tr>
            <td class=number><font size=2>2.</font></td>
            <td class=text><font size=2>Locate and click the following registry key: </font>
            <div class=indent><strong><font size=2>HKEY_LOCAL_MACHINE/System/CurrentControlSet/Services/Resvc/Parameters/ </font></strong></div>
            </td>
        </tr>
        <tr>
            <td class=number><font size=2>3.</font></td>
            <td class=text><font size=2>On the <strong>Edit</strong> menu, click <strong>Add Value</strong>, and then add the following registry value: </font>
            <div class=indent><font size=2>Value Name: CheckConnectorRestrictions<br>Data Type: REG_DWORD<br>Radix: Hexadecimal<br>Value: 1 </font></div>
            </td>
        </tr>
        <tr>
            <td class=number><font size=2>4.</font></td>
            <td class=text><font size=2>Quit Registry Editor.</font></td>
        </tr>
        <tr>
            <td class=number><font size=2>5.</font></td>
            <td class=text><font size=2>Restart the Microsoft Exchange Routing Engine service and the Simple Mail Transfer Protocol (SMTP) services for this change to take effect.</font></td>
        </tr>
    </tbody>
</table>
</p>
<p>&nbsp;&nbsp;参考以下信息</p>
<h1 class=title><font size=3>XCON: Connector Delivery Restrictions May Not Work Correctly<br></font><a title=http://support.microsoft.com/kb/277872/en-us href="http://support.microsoft.com/kb/277872/en-us"><u><font color=#0066cc>http://support.microsoft.com/kb/277872/en-us</font></u></a></h1>
<p class=title>&nbsp;</p>
<strong>限制用户发送内部<br></strong>可以通过尝试删除该用户安全选项中<span>self</span><span>帐户的</span><span>send as</span><span>（代理发送）</span><span>权限来解决该问题。</span>
<p>&nbsp;<span>有关如何修改</span><span>send as</span><span>权限的详细信息，请参考下面的链接：</span></p>
<p><span>HOW TO: </span><span>在</span><span> Exchange 2000 Server </span><span>中授予</span><span>&#8220;</span><span>代理发送</span><span>&#8221;</span><span>和</span><span>&#8220;</span><span>代表发送</span><span>&#8221;</span><span>权限</span></p>
<p><span>http://support.microsoft.com/kb/327000/zh-cn</span></p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/49554.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-09-26 15:18 <a href="http://www.cnitblog.com/joyclear/archive/2008/09/26/49554.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007环境中，更改outlook规则和通知大小设定</title><link>http://www.cnitblog.com/joyclear/archive/2008/08/22/48232.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 22 Aug 2008 03:28:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/08/22/48232.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/48232.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/08/22/48232.html#Feedback</comments><slash:comments>4</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/48232.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/48232.html</trackback:ping><description><![CDATA[Exchange 2000/2003中，outlook的规则和通知大小限制为32K<br>Exchange 2007中，Outlook的规则和通知大小默认为64K,最大可以更改为256K<br><br>Set-Mailbox -RulesQuota 256k
<img src ="http://www.cnitblog.com/joyclear/aggbug/48232.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-08-22 11:28 <a href="http://www.cnitblog.com/joyclear/archive/2008/08/22/48232.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>如何将所有缓存模式客户端配置为使用联机全局地址列表来解析不明确的名称</title><link>http://www.cnitblog.com/joyclear/archive/2008/08/18/48110.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 18 Aug 2008 03:02:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/08/18/48110.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/48110.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/08/18/48110.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/48110.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/48110.html</trackback:ping><description><![CDATA[<span style="COLOR: red">在缓存 Exchange 模式下，Outlook&nbsp;2003 即便在连接到服务器时，也使用脱机通讯簿来解析不明确的名称。<font color=#000000>若要配置 Outlook 以使用联机全局地址列表，请执行下列步骤。<br>
<ol>
    <li>
    <p>在运行 Outlook 的计算机上启动注册表编辑器。</p>
    <li>
    <p>导航至下面的一个注册表项： </p>
    <ul>
        <li><tt>HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Outlook\Cached Mode </tt><br>
        <li><tt>HKEY_LOCAL_MACHINE\Software \Microsoft\Office\11.0\Outlook\Cached Mode </tt><br></li>
    </ul>
    <div class=alert>
    <table width="100%">
        <tbody>
            <tr>
                <th align=left><img class=note src="http://i.technet.microsoft.com/Bb124284.note(zh-cn,EXCHG.65).gif">注意：</th>
            </tr>
            <tr>
                <td>可能必须创建 Cached Mode 项。 </td>
            </tr>
        </tbody>
    </table>
    </div>
    <li>
    <p>添加新的值： </p>
    <p>参数：<strong>ANR Include Online GAL </strong></p>
    <p>类型：<strong>DWORD _ </strong></p>
    <p>值：<strong>0 </strong>或 <strong>1 </strong></p>
    <p>其中各个数据值分别表示以下含义： </p>
    <p>0 = Outlook&nbsp;2003 缓存模式的默认值，将使用脱机通讯簿来执行不明确名称的解析搜索。 </p>
    <p>1 = 更改缓存模式，以便连接到服务器地址列表来执行不明确名称的解析搜索。该值将强制与服务器地址列表建立更多的远程过程调用 (RPC) 连接。</p>
    </li>
</ol>
</font><br></span>
<img src ="http://www.cnitblog.com/joyclear/aggbug/48110.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-08-18 11:02 <a href="http://www.cnitblog.com/joyclear/archive/2008/08/18/48110.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>如何更改脱机地址簿的默认路径</title><link>http://www.cnitblog.com/joyclear/archive/2008/08/18/48109.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 18 Aug 2008 02:35:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/08/18/48109.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/48109.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/08/18/48109.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/48109.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/48109.html</trackback:ping><description><![CDATA[<ol>
    <li>
    <p>在客户端计算机上，关闭 Outlook 并创建合适的文件路径（例如，D:\OAB）。</p>
    <li>
    <p>在运行 Outlook 的客户端计算机上，启动注册表编辑器。</p>
    <li>
    <p>导航到 HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows MEssaging Subsystem\Profiles\&lt;默认 Microsoft Outlook 配置文件&gt;\13dbb0c8aa05101a9bb000aa002fc45a</p>
    <li>
    <p>添加新的字符串值： </p>
    <p>参数：<strong>001e660e</strong></p>
    <p>值：&lt;<strong><em>脱机通讯簿文件的路径</em></strong>&gt; </p>
    <p>类型：<strong>字符串值 </strong></p>
    <p>例如： </p>
    <p>参数：001e660e </p>
    <p>值：D:\OAB </p>
    <p>类型：字符串值 </p>
    </li>
</ol>
<img src ="http://www.cnitblog.com/joyclear/aggbug/48109.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-08-18 10:35 <a href="http://www.cnitblog.com/joyclear/archive/2008/08/18/48109.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Few, little , a few , a little</title><link>http://www.cnitblog.com/joyclear/archive/2008/08/11/47913.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 11 Aug 2008 15:21:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/08/11/47913.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/47913.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/08/11/47913.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/47913.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/47913.html</trackback:ping><description><![CDATA[<table cellSpacing=0 cellPadding=0 width=540 border=0>
    <tbody>
        <tr>
            <td class=p2 width=760 colSpan=3><strong>few, little, a few, a little</strong></td>
        </tr>
        <tr>
            <td width=20 height=254>&nbsp;</td>
            <td class=p2 vAlign=top width=520 height=254><br>(a) few + 可数名词, (a) little + 不可数名词<br>　a few / a little 为肯定含义，还有一点<br>　few / little　为否定含义，没有多少了。<br>　He has a few friends.　　　他有几个朋友。<br>　He has few friends.　　　 他几乎没有朋友。<br>　We still have a little time. 我们还有点时间。<br>　There is little time left.几乎没剩下什么时间了。<br><br>典型例题:<br>　 Although he 's wealthy，he spends___ on clothes.<br>　 A. little　 B. few　C. a little　 D. a few<br>　 答案： A. spend所指的是钱，不可数，只能用little或 a little. 本句为although引导的让步状语从句，由句意知后句为否定含义，因此应用little表示几乎不。<br><br>固定搭配:<br>　　only a few (=few)　 not a few (=many)　 quite a few (=many)<br>　　many a (=many)<br>　　Many books were sold. <br>　　Many a book was sold. <br>　　 卖出了许多书。<br></td>
        </tr>
    </tbody>
</table>
<img src ="http://www.cnitblog.com/joyclear/aggbug/47913.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-08-11 23:21 <a href="http://www.cnitblog.com/joyclear/archive/2008/08/11/47913.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>如何在outlook 2003中查看IMF SCL的值</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/30/47301.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Wed, 30 Jul 2008 07:21:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/30/47301.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/47301.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/30/47301.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/47301.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/47301.html</trackback:ping><description><![CDATA[<h1 class=title>How to verify the Intelligent Message Filter SCL rating in Outlook 2003</h1>
<script type=text/javascript>function loadTOCNode(){}</script>
<div class=articleProperty>
<table>
    <tbody>
        <tr>
            <td>Article ID</td>
            <td>:</td>
            <td>895091</td>
        </tr>
        <tr>
            <td>Last Review</td>
            <td>:</td>
            <td>October 11, 2007</td>
        </tr>
        <tr>
            <td>Revision</td>
            <td>:</td>
            <td>3.1</td>
        </tr>
    </tbody>
</table>
</div>
<div class=toc id=tocDiv style="DISPLAY: block">
<h5>On This Page</h5>
<div depth="1"><a onclick="return tocScrollTo(this);" href="http://support.microsoft.com/kb/895091/en-us#"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/downarrow.gif"><span class=tocTxt><u><font color=#800080>SUMMARY</font></u></span></a>
<div class=tocLine></div>
</div>
<div depth="1"><a onclick="return tocScrollTo(this);" href="http://support.microsoft.com/kb/895091/en-us#"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/downarrow.gif"><span class=tocTxt><u><font color=#800080>MORE INFORMATION</font></u></span></a>
<div class=tocLine>
<div depth="2"><a onclick="return tocScrollTo(this);" href="http://support.microsoft.com/kb/895091/en-us#"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/downarrow.gif"><span class=tocTxt><u><font color=#800080>How to install the SCL Extension Form in Outlook 2003</font></u></span></a>
<div class=tocLine></div>
</div>
<div depth="2"><a onclick="return tocScrollTo(this);" href="http://support.microsoft.com/kb/895091/en-us#"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/downarrow.gif"><span class=tocTxt><u><font color=#800080>How to add the SCL rating field into the column header of Outlook folders</font></u></span></a>
<div class=tocLine></div>
</div>
</div>
</div>
<div depth="1"><a onclick="return tocScrollTo(this);" href="http://support.microsoft.com/kb/895091/en-us#"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/downarrow.gif"><span class=tocTxt><u><font color=#800080>REFERENCES</font></u></span></a>
<div class=tocLine></div>
</div>
</div>
<script type=text/javascript>
var sectionFilter = "type != 'notice' && type != 'securedata' && type != 'querywords'";
var tocArrow = "/library/images/support/kbgraphics/public/en-us/downarrow.gif";
var depthLimit = 10;
var depth3Limit = 10;
var depth4Limit = 5;
var depth5Limit = 3;
var tocEntryMinimum = 1;
</script>
<script src="/common/script/gsfx/kbtoc.js?12" type=text/javascript></script>
<noscript><style>.toc{display: none;}</style></noscript>
<div class=section>
<h2 class=subTitle id=tocHeadRef>SUMMARY</h2>
<script type=text/javascript>loadTOCNode(1, 'summary');</script>
<div class=sbody>The Microsoft Exchange Server Intelligent Message Filter (IMF) evaluates incoming messages for recognizable patterns. Then, the IMF assigns a spam confidence level (SCL) rating to the message. This rating is based on the probability that the message is unsolicited commercial e-mail ("spam"). This SCL rating is used to determine how the Exchange IMF handles messages. <br><br>Sometimes you may have to know whether the IMF works by checking the SCL rating of incoming messages. This article describes how to verify IMF functions by checking messages' SCL rating values in Microsoft Office Outlook 2003. This article discusses the following topics:
<table class="list ul">
    <tbody>
        <tr>
            <td class=bullet>&#8226;</td>
            <td class=text>How to install the SCL Extension Form in Outlook 2003</td>
        </tr>
        <tr>
            <td class=bullet>&#8226;</td>
            <td class=text>How to add the SCL rating field into the column header of Outlook folders</td>
        </tr>
    </tbody>
</table>
<p class=topOfPage><a href="http://support.microsoft.com/kb/895091/en-us#top"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/uparrow.gif"><u><font color=#800080>Back to the top</font></u></a></p>
</div>
<h2 class=subTitle id=tocHeadRef>MORE INFORMATION</h2>
<script type=text/javascript>loadTOCNode(1, 'moreinformation');</script>
<div class=sbody>
<h3 id=tocHeadRef>How to install the SCL Extension Form in Outlook 2003</h3>
<script type=text/javascript>loadTOCNode(2, 'moreinformation');</script>
To read the SCL rating from messages in Outlook 2003, install the SCL extension Form first. To do this, follow these steps:
<table class="list ol">
    <tbody>
        <tr>
            <td class=number>1.</td>
            <td class=text>Open Notepad. To do this, click <strong class=uiterm>Start</strong>, click <strong class=uiterm>Run</strong>, type <span class=userInput>notepad.exe</span>, and then click <strong class=uiterm>OK</strong>. </td>
        </tr>
        <tr>
            <td class=number>2.</td>
            <td class=text>Copy and then paste the following text into Notepad.<code>
            <pre class=code>[Description]
            MessageClass=IPM.Note
            CLSID={00020D31-0000-0000-C000-000000000046}
            DisplayName=SCL Extension Form
            Category=Standard
            Subcategory=Form
            Comment=This forms allows the SCL to be viewed as a column
            LargeIcon=IPML.ico
            SmallIcon=IPMS.ico
            Version=1.0
            Locale=enu
            Hidden=1
            Owner=Microsoft Corporation
            Contact=Your Name
            [Platforms]
            Platform1=Win16
            Platform2=NTx86
            Platform9=Win95
            [Platform.Win16]
            CPU=ix86
            OSVersion=Win3.1
            [Platform.NTx86]
            CPU=ix86
            OSVersion=WinNT3.5
            [Platform.Win95]
            CPU=ix86
            OSVersion=Win95
            [Properties]
            Property01=SCL
            [Property.SCL]
            Type=3
            NmidInteger=0x4076
            DisplayName=SCL
            [Verbs]
            Verb1=1
            [Verb.1]
            DisplayName=&amp;Open
            Code=0
            Flags=0
            Attribs=2
            [Extensions]
            Extensions1=1
            [Extension.1]
            Type=30
            NmidPropset={00020D0C-0000-0000-C000-000000000046}
            NmidInteger=1
            Value=1000000000000000</pre>
            </code></td>
        </tr>
        <tr>
            <td class=number>3.</td>
            <td class=text>Save this text file as <strong class=uiterm>Scl.cfg</strong>, and then exit Notepad. </td>
        </tr>
        <tr>
            <td class=number>4.</td>
            <td class=text>Save the Scl.cfg file to the following location:
            <div class=indent>\Program Files\Microsoft Office\OFFICE11\FORMS\1033</div>
            </td>
        </tr>
        <tr>
            <td class=number>5.</td>
            <td class=text>Start Outlook 2003 by using a profile that is configured for the mailbox on the server that is running Microsoft Exchange Server 2003 together with IMF.</td>
        </tr>
        <tr>
            <td class=number>6.</td>
            <td class=text>On the <strong class=uiterm>Tools</strong> menu, click <strong class=uiterm>Options</strong>.</td>
        </tr>
        <tr>
            <td class=number>7.</td>
            <td class=text>On the <strong class=uiterm>Other</strong> tab, click <strong class=uiterm>Advanced Options</strong>.</td>
        </tr>
        <tr>
            <td class=number>8.</td>
            <td class=text>In the <strong class=uiterm>Advanced Options</strong> dialog box, click <strong class=uiterm>Custom Forms</strong>.</td>
        </tr>
        <tr>
            <td class=number>9.</td>
            <td class=text>In the <strong class=uiterm>Options</strong> dialog box, click <strong class=uiterm>Manage Forms</strong>.</td>
        </tr>
        <tr>
            <td class=number>10.</td>
            <td class=text>In the <strong class=uiterm>Forms Manager</strong> dialog box, click <strong class=uiterm>Install</strong>.</td>
        </tr>
        <tr>
            <td class=number>11.</td>
            <td class=text>Locate the Scl.cfg file. Then, click <strong class=uiterm>OK</strong> to confirm that the file was installed. If you successfully installed it, the <strong class=uiterm>SCL Extension Form</strong> item is listed in the Personal Forms library.</td>
        </tr>
    </tbody>
</table>
<p class=topOfPage><a href="http://support.microsoft.com/kb/895091/en-us#top"><img alt="" src="http://support.microsoft.com/library/images/support/kbgraphics/public/en-us/uparrow.gif"><u><font color=#800080>Back to the top</font></u></a></p>
<h3 id=tocHeadRef>How to add the SCL rating field into the column header of Outlook folders</h3>
<script type=text/javascript>loadTOCNode(2, 'moreinformation');</script>
After you install the SCL extension Form, you still will not see the messages' SCL rating values right away. You have to add the SCL rating field to the column header. When you do this, you can automatically check the messages' SCL rating values that are listed in the SCL column in Outlook 2003. <br><br>To add the SCL rating field, follow these steps:
<table class="list ol">
    <tbody>
        <tr>
            <td class=number>1.</td>
            <td class=text>In Outlook 2003, click <strong class=uiterm>Inbox</strong>.</td>
        </tr>
        <tr>
            <td class=number>2.</td>
            <td class=text>On the <strong class=uiterm>View</strong> menu, click <strong class=uiterm>Arrange By</strong>, and then click <strong class=uiterm>Custom</strong>.</td>
        </tr>
        <tr>
            <td class=number>3.</td>
            <td class=text>In the <strong class=uiterm>Customize View: Messages</strong> dialog box, click <strong class=uiterm>Fields</strong>.</td>
        </tr>
        <tr>
            <td class=number>4.</td>
            <td class=text>In the <strong class=uiterm>Show Fields</strong> dialog box, click the <strong class=uiterm>Select available fields from</strong> list, and then click <strong class=uiterm>Forms</strong>.</td>
        </tr>
        <tr>
            <td class=number>5.</td>
            <td class=text>In the <strong class=uiterm>Select Enterprise forms for this folder</strong> dialog box, click <strong class=uiterm>Personal Forms</strong> on the list.</td>
        </tr>
        <tr>
            <td class=number>6.</td>
            <td class=text>Locate <strong class=uiterm>SCL Extension From</strong> in the left pane, and then click <strong class=uiterm>Add</strong> to add it to the right pane. Click <strong class=uiterm>Close</strong>.</td>
        </tr>
        <tr>
            <td class=number>7.</td>
            <td class=text>In the <strong class=uiterm>Show Fields</strong> dialog box, locate the SCL in the left pane, and then click <strong class=uiterm>Add</strong> to add it to the right pane.</td>
        </tr>
        <tr>
            <td class=number>8.</td>
            <td class=text>Click <strong class=uiterm>OK</strong> two times.</td>
        </tr>
        <tr>
            <td class=number>9.</td>
            <td class=text>In the Inbox, you will see a new column that is named SCL in the column header. All the messages in the Inbox show their SCL rating values under the SCL column. </td>
        </tr>
    </tbody>
</table>
<strong>Note</strong> You can also use this procedure in folders that are separate from the Inbox to check the SCL rating values for the messages in these folders.</div>
</div>
<img src ="http://www.cnitblog.com/joyclear/aggbug/47301.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-30 15:21 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/30/47301.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007服务器启动后，Information Store和System Attendant服务不能自动启动</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/25/47130.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 25 Jul 2008 08:40:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/25/47130.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/47130.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/25/47130.html#Feedback</comments><slash:comments>4</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/47130.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/47130.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;SA和Information服务不会自动启动，手动启动正常<br><br>1) 在Exchange服务器上添加下面的注册表键值来延迟SA的启动时间<br><br>HKLM\System\CurrentControlSet\Services\MSExchangeSA\Parameters<br>Key (Type:DWORD): BootPause <br>Value: 300 (The value is in seconds &lt;decimal&gt;)<br><br>2) 添加下面的键值让Exchange Information Store 和Exchange Active Directory Topology 服务依赖于SA服务. <br><br>HKLM\System\CurrentControlSet\Services\MSExchangeADTopology<br>Key (Type: Multi_String): DependOnService<br>Value: MSExchangeSA<br><br>HKLM\System\CurrentControlSet\Services\MSExchangeIS<br>Key (Type: Multi_String): DependOnService<br>Value: MSExchangeSA<br><br>3) 重启Exchange服务器<br><br>
<img src ="http://www.cnitblog.com/joyclear/aggbug/47130.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-25 16:40 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/25/47130.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange2007 SPAM流程图</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/22/47016.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Tue, 22 Jul 2008 09:43:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/22/47016.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/47016.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/22/47016.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/47016.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/47016.html</trackback:ping><description><![CDATA[<p><br><img height=768 alt="" src="http://www.cnitblog.com/images/cnitblog_com/joyclear/Exchange_SPAM.JPG" width=331 border=0></p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/47016.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-22 17:43 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/22/47016.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007 OWA及发送邮件大小设定</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/18/46883.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 18 Jul 2008 07:15:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/18/46883.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/46883.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/18/46883.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/46883.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/46883.html</trackback:ping><description><![CDATA[<p>在Exchange 2007中的郵件傳送與接收大小的限制有下列幾個檢查點</p>
<p><a title=http://technet.microsoft.com/en-us/library/bb124345.aspx href="http://technet.microsoft.com/en-us/library/bb124345.aspx">http://technet.microsoft.com/en-us/library/bb124345.aspx</a></p>
<ul type=disc>
    <li>Origanizational Limit </li>
    <li>Global Limit </li>
    <li>Connector Limit </li>
    <li>Server Limit </li>
    <li>User Limit</li>
</ul>
<p>&nbsp;</p>
<p>在沒有Edge的情況下，Organizational以及User的收及發都是未設限，亦即Unlimited</p>
<p>假設整個ORG中你只有一台Hub Transport，以及只有一條Send Connector的話</p>
<p>那麼預設使用者寄出去及收進來都只有10MB．</p>
<p>因為預設Hub Transport上的Send &amp; Receive Connector的最大message size都是10MB</p>
<p>你可以利用Set-SendConnector -MaxMessageSize以及Set-ReceiveConnector -MaxMessageSize cmdlet來改變預設的郵件傳送及接收大小</p>
<p>至於OWA預設在選取要加入的附件檔案的大小是30000 KB，你可以依照下面的作法做適當的修改</p>
<p><a title=http://technet.microsoft.com/en-us/library/aa996835.aspx href="http://technet.microsoft.com/en-us/library/aa996835.aspx">http://technet.microsoft.com/en-us/library/aa996835.aspx</a></p>
<p>要注意的是，即使OWA預設可上傳的附件檔大小為30000KB,不代表使用者就可以真的將30000KB大小的附件檔寄出</p>
<p>因為還是會受限於Send Connector預設10MB大小的限制<br><br>&nbsp; </p>
<p align=left>解決方法：使用ADSI EDIT設定</p>
<p style="COLOR: red" align=left>Configuration--&gt;CN=Service--&gt;CN=Microsoft Exchange--&gt;CN=&lt;Exchange ORG. Name&gt;--&gt;CN=Global Settings--&gt;CN=Message Delivery--&gt;滑鼠右鍵--&gt;內容</p>
<p align=left><span style="COLOR: red">delivContLength：&lt;10240&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (0~2097151KB)&nbsp;&nbsp;　預設值為10MB，最大可以設為2097151KB (2GB)<br>&nbsp; submissionContLenght：&lt;10240&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (0~2097151KB)&nbsp;&nbsp;&nbsp;&nbsp; 同上<br>&nbsp; msExchReciplimit：&lt;5000&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (0~2147483647)&nbsp;&nbsp; 不用改</span></p>
<p align=left>&nbsp;</p>
<p align=left>&nbsp;</p>
<p style="COLOR: #3366ff" align=left>Exchange 2007傳送大小，使用MAPI時會受限於Global limits、Organizational limits、使用者信箱傳送大小的限制、Pickup大小的限制、集線傳輸規則的附件檔大小限制、Connector limits、OWA 2007 (Web.config file)的上傳下載大小限制。</p>
<p align=left>&nbsp;</p>
<p style="COLOR: #3366ff" align=left>&nbsp;&nbsp;&nbsp; 傳送大小的限制原則是：使用者的傳送大小或接收大小取決於使用者信箱的傳送大小限制之設定，若保持預設(沒有特別指定)，再由Global及ORG.兩者的傳送大小限制來決定，但預設上，Global是限制10MB，而ORG是沒有限制，因此Global與ORG之間再取最小值，所以若使用者信箱沒有特別設定傳送大小限制，預設值會被限制在10MB。</p>
<p align=left>&nbsp;</p>
<p align=left>&nbsp;以上為純Exchange 2007安裝時的情況,若是由Exchange 2003或Exchange 2000升級上來的,則Global會保留原有設定, 一般人比較容易疏忽的是Global設定,因為這是舊版本Exchange的設定,只能由Exchange 2000或2003的管理介面去檢視或設定,若是純Exchange 2007的安裝,並沒有直接的管理介面或指令去指定,必須透過ADSI工具至AD的Configuration中設定。</p>
<p align=left>&nbsp;</p>
<p align=left>Best regards.</p>
<p align=left>&nbsp;</p>
<p align=left>Frank Hsieh</p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/46883.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-18 15:15 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/18/46883.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007 POP3寄件权限问题</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/18/46876.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Fri, 18 Jul 2008 05:27:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/18/46876.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/46876.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/18/46876.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/46876.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/46876.html</trackback:ping><description><![CDATA[<span>发现台湾微软技术社区还是比较热闹的，而且讨论问题也很专业~<br>&nbsp;
<p align=left><font face="Times New Roman" size=2>Exchange server 2007已經開啟POP3、IMAP4服務，</font></p>
<p align=left><font face="Times New Roman" size=2>LoginType 採用預設的 SecureLogin 加密方式，</font></p>
<p align=left><font face="Times New Roman">用戶端使用 Outlook Express &amp; Windows Mail，</font></p>
<p align=left><font face="Times New Roman">在進階的部分也都開啟了使用 SSL 加密 port 的選項，</font></p>
<p align=left><font face="Times New Roman" size=2>使用 POP3 或 IMAP4 <font color=#ff0000>收信也都正常</font>，</font></p>
<p align=left><font face="Times New Roman">但是在某部分使用者寄信的時候，會出現下列錯誤而無法寄出郵件</font></p>
<p><font face=新細明體></font>&nbsp;<font face=新細明體><span>====</span></font></p>
<p align=left><font face=新細明體><span>無法傳送郵件，因為伺服器拒絕寄件者的電子郵件地址。寄件者的地址是 <span><a title="mailto:abc@abc.com.tw'" href="&#109;&#97;&#105;&#108;&#116;&#111;&#58;&#97;&#98;&#99;&#64;&#97;&#98;&#99;&#46;&#99;&#111;&#109;&#46;&#116;&#119;&#39;"><font color=#0000ff>abc@abc.com.tw'</font></a></span>。主旨<span> '1', </span>帳戶<span>: 'abc', </span>伺服器<span>: 'cas.abc.com.tw', </span>通訊協定<span>: SMTP, </span>伺服器回應<span>: '550 5.7.1 Client does not have permissions to send as this sender', </span>連接埠<span>: 25, </span>安全<span>(SSL): </span>是<span>, </span>伺服器錯誤<span>: 550, </span>錯誤碼<span>: 0x800CCC78</span></span></font></p>
<p align=left><font face=新細明體><span><span>====</span></span></font></p>
<p align=left><font face=新細明體><span><span>看起來似乎是調整一下權限即可，</span></span></font></p>
<p align=left><font face=新細明體><span><span>不過卻不知道從何下手，請問有人解決過這個問題嗎？</span></span></font></p>
<br>
<p>Hi Joseph,</p>
<p align=left>&nbsp;</p>
<p align=left>再仔細分析你的情況,假設是Exchange 2000 或Exchange 2003升級上來的,那麼曾經加入或現在還是Enterprise Admins或Domain Admins的帳號,在升級至Exchange 2007後,最有可能發生這情況,那是因為加入了這些群組後,AD的繼承自動會被拿掉,因此會造成升級後OWA及POP3有問題。Administrator、Enterprise admins、Domain Admins等帳號或群組的成員有許多權限是被設為『拒絕』的。</p>
<p align=left>&nbsp;</p>
<p align=left>你可以使用<font color=#ff0000><strong>『Active Directory使用者及電腦』</strong></font>程式,將檢視選擇為<font color=#ff0000><strong>『進階功能』,</strong></font>然後點選『有問題的帳號』--&gt;內容--&gt;安全性標籤,檢查看看有沒有SELF帳號,若沒有把它加進來(選擇新增--&gt;手動輸入SELF--&gt;確定),正常應有此帳號,接著在<strong><font color=#ff0000>『安全性</font><font color=#ff0000>』</font></strong>標籤頁選擇『進階』,檢查一下<font color=#0000ff><strong><u>『允許從父項繼承權限套用到這個物件和所有的子物件,包括明確定義於此的項目(A)』</u></strong></font>選項是否未勾選,一般的帳號應會勾選起來,若沒有勾選,接著直接點選『預設』按鈕,會自動勾選起來,然後再按確定--&gt;等同步後再重試一次寄信,記得按『預設』按鈕,它會把原來該有的權限加入。</p>
<p align=left>&nbsp;</p>
<p align=left>即使有SELF帳號<font color=#0000ff><strong><u>,『允許從父項繼承權限套用到這個物件和所有的子物件,包括明確定義於此的項目(A)』</u></strong></font>選項也有勾選,也應按一下『預設』按鈕,因為有些權限有可能某些因素被拿掉。</p>
<p align=left>&nbsp;</p>
<p align=left>Best regards,</p>
<p align=left>Frank Hsieh</p>
</span>
<img src ="http://www.cnitblog.com/joyclear/aggbug/46876.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-18 13:27 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/18/46876.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007 传输组件</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/14/46710.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 14 Jul 2008 09:01:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/14/46710.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/46710.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/14/46710.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/46710.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/46710.html</trackback:ping><description><![CDATA[<table style="WIDTH: 730px; BORDER-COLLAPSE: collapse; HEIGHT: 266px" cellSpacing=0 cellPadding=3 border=1>
    <tbody>
        <tr>
            <td><strong>Component&nbsp;</strong></td>
            <td><strong>Description</strong></td>
        </tr>
        <tr>
            <td>Submission Queue</td>
            <td>Stores All messages on disk until processed</td>
        </tr>
        <tr>
            <td>Store Driver</td>
            <td>Retrieves messages from sender's outbox</td>
        </tr>
        <tr>
            <td>MicrosoftExchange Mail Submission service</td>
            <td>Notifies a Hub Transport Server role in the local Active Directory site when a message is avaiable for retrieval from a sender's outbox</td>
        </tr>
        <tr>
            <td>Pickup directory</td>
            <td>Submits message to the Submission queue</td>
        </tr>
        <tr>
            <td>Categorizer</td>
            <td>Processes one message at a time from the Submission queue</td>
        </tr>
    </tbody>
</table>
<br><strong>Submission Queue<br></strong>在边缘传输服务器和中心传输服务器上，当Exchange Transport服务启动时，分类进程(Categorizer)会创建一个递交队列。递交队列存储所有的邮件在硬盘上，直到分类进程决定以下一步传递。所有的邮件都要递交到递交队列后，然后才能被分类。当一份邮件被分类进程执行后，它仍然保留在递交队列里面，成功分类后，邮件移除出递交队列。<br><strong>发送到递交队列的邮件方式：</strong><br>1.从SMTP接受器接受的邮件<br>2.在Pickup目录的邮件<br>3.递交到Store driver的邮件<br>4.失败传递后重新递交的邮件<br><br><strong>Store Driver</strong><br>当一份邮件在用户发件箱进行发送时，存储驱动从发送信箱接受邮件，递交到递交队列。当一份邮件成功添加到递交队列，邮件从发件箱移动到已发送邮箱。<br>存储驱动负责将邮件在Outbox中的MAPI格式，转换为S/TNEF(Summary Transport Neutral Encapsulation Format)格式，如果存储驱动不能转换，NDR报告产生。<br><br><strong>Microsoft Exchange Mail Submission Service<br></strong>Microsoft Exchange Mail Submission Service是运行在Mailbox服务器上的提示服务。当一份邮件在发送者outbox中可以被接受时，通知Hub Transport Server服务器。Store Driver接受邮件。<br>当在一个AD站点中有多台Hub Transport服务器，Microsoft Exchange Mail Submission services尝试平均发布通知。<br><br><strong>Pickup Directory<br></strong>大部分的邮件传输通过SMTP接受器或者通过Store Driver递交，但是邮件也能通过在边缘或中心传输服务器的Pickup目录进行传递。<br>放置在Pickup目录的邮件递交Submission Queue,当在递交队列中被递交到分类进程后，邮件从Pickup目录中删除。放置在Pickup目录中的邮件需要符合适当的格式和读/写权限。<br><br>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span lang=EN-US><font face=Calibri><strong>Categorizer<o:p></o:p></strong></font></span></p>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">分类进程从递交队列中提取邮件，在递交队列中总是更早的邮件被优先提取。</span></p>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">在边缘服务器，分类进程仅仅处理收件人地址是否符合这一条件，然后邮件直接传递到传输队列。通过传输队列，邮件路由到中心传输服务器。</span></p>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">在中心传输服务器上，分类进程执行下列的任务：</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l1 level1 lfo1"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>1.</font><span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">判断和检查收件人</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l1 level1 lfo1"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>2.</font><span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">多收件人邮件进行分叉</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l1 level1 lfo1"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>3.</font><span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">判断路由路径</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l1 level1 lfo1"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>4.</font><span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">转换内容格式</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l1 level1 lfo1"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>5.</font><span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">应用组织邮件策略</span></p>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span lang=EN-US><o:p><font face=Calibri>&nbsp;</font></o:p></span></p>
<p class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">单个</span><span lang=EN-US><font face=Calibri>AD</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">站点中邮件的传递流向工作</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l0 level1 lfo2"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>1．</font><span style="FONT: 7pt 'Times New Roman'">&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">当一份邮件递交到邮箱服务器邮箱存储上时，邮件流开始。如果客户端是</span><span lang=EN-US><font face=Calibri>office outlook</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">客户端，邮件通过</span><span lang=EN-US><font face=Calibri>MAPI</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">提交，邮件直接写在用户</span><span lang=EN-US><font face=Calibri>outbox</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">中。</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l0 level1 lfo2"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>2．</font><span style="FONT: 7pt 'Times New Roman'">&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">当</span><span lang=EN-US><font face=Calibri>Microsoft Exchange Mail Submission service</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">检测到邮件可用</span><span lang=EN-US><font face=Calibri>(</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">在</span><span lang=EN-US><font face=Calibri>outbox</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">中</span><span lang=EN-US><font face=Calibri>)</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">，它选择一台可用的中心传输服务器角色，递交一个邮件通知给</span><span lang=EN-US><font face=Calibri>Store Driver</font></span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l0 level1 lfo2"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>3．</font><span style="FONT: 7pt 'Times New Roman'">&nbsp; </span></span></span><span lang=EN-US><font face=Calibri>Store Driver(</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">中心传输服务器的传输服务组件</span><span lang=EN-US><font face=Calibri>)</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">使用</span><span lang=EN-US><font face=Calibri>MAPI</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">连接到用户的</span><span lang=EN-US><font face=Calibri>outbox,</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">收集所有需要发送的邮件。将邮件递交到递交队列，然后将邮件从</span><span lang=EN-US><font face=Calibri>outbox</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">移动到已发送邮箱。</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l0 level1 lfo2"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>4．</font><span style="FONT: 7pt 'Times New Roman'">&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">当邮件目的是同一个</span><span lang=EN-US><font face=Calibri>AD</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">站点的邮箱服务器，邮件被提交到</span><span lang=EN-US><font face=Calibri>Local Delivery Queue</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">，然后</span><span lang=EN-US><font face=Calibri>store driver </font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">通过</span><span lang=EN-US><font face=Calibri>MAPI</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">传递邮件到邮箱服务器角色。</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l0 level1 lfo2"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>5．</font><span style="FONT: 7pt 'Times New Roman'">&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">当邮件目的是另一个</span><span lang=EN-US><font face=Calibri>AD</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">站点的邮件服务器，中心传输服务器使用</span><span lang=EN-US><font face=Calibri>AD</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">站点链接信息来判断到目的站点的路由，当路径确定后，中心传输服务器会直接连接到远程站点的服务器。如果在目的站点没有中心传输服务器可用，邮件将被路由到离目的站点最近的中心传输服务器。</span></p>
<p class=MsoListParagraph style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-char-indent-count: 0; mso-list: l0 level1 lfo2"><span lang=EN-US style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><span style="mso-list: Ignore"><font face=Calibri>6．</font><span style="FONT: 7pt 'Times New Roman'">&nbsp; </span></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">当邮件目的是</span><span lang=EN-US><font face=Calibri>Internet</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin">，中心传输服务器提交邮件到边缘服务器。</span></p>
<br><br><br>参考自MOC教材<br><br><br>
<img src ="http://www.cnitblog.com/joyclear/aggbug/46710.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-14 17:01 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/14/46710.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange2003中对于 "对传入邮件执行反向 DNS 查找" 选项功能的错误理解</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/14/46692.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 14 Jul 2008 02:34:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/14/46692.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/46692.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/14/46692.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/46692.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/46692.html</trackback:ping><description><![CDATA[<h1 class=title>The "Perform Reverse DNS Lookup for Incoming Messages" Option Is for Host Name Resolution</h1>
<div class=appliesToLink><a href="http://support.microsoft.com/kb/297412/en-us#appliesto"><u><font color=#800080>View products that this article applies to.</font></u></a></div>
<script>function loadTOCNode(){}</script>
<div class=articleProperty>
<table>
    <tbody>
        <tr>
            <td>Article ID</td>
            <td>:</td>
            <td>297412</td>
        </tr>
        <tr>
            <td>Last Review</td>
            <td>:</td>
            <td>December 3, 2007</td>
        </tr>
        <tr>
            <td>Revision</td>
            <td>:</td>
            <td>4.5</td>
        </tr>
    </tbody>
</table>
</div>
<div class=notice>This article was previously published under Q297412</div>
<div class=section>
<h2 class=subTitle id=tocHeadRef>SUMMARY</h2>
<script type=text/javascript>loadTOCNode(1, 'summary');</script>
<div class=sbody>This article describes the <strong class=uiterm>Perform Reverse DNS Lookup for Incoming Messages</strong> option and how its function can be misinterpreted by Exchange administrators. </div>
<h2 class=subTitle id=tocHeadRef>MORE INFORMATION</h2>
<script type=text/javascript>loadTOCNode(1, 'moreinformation');</script>
<div class=sbody>The <strong class=uiterm>Perform Reverse DNS Lookup for Incoming Messages</strong> option is located on the <strong class=uiterm>Default Virtual SMTP Server Properties</strong> dialog box: On the <strong>Delivery</strong> tab, click <strong>Advanced</strong>. Exchange administrators may misinterpret the function of this option: They may expect Exchange to reject e-mail messages that originate from unresolved domains.<br><br>Some messaging systems verify the existence of the e-mail domain of the sender before they accept a "Mail from: user@domain.com" Simple Mail Transfer Protocol (SMTP) entry at the beginning of a new message delivery session. If the domain name cannot be resolved by means of Domain Name System (DNS), the session is disconnected and an error 501 is generated. This behavior is mainly used to prevent you from receiving spam (unsolicited e-mail messages). Microsoft Exchange Server 5.5 and later do not use this feature. <br><br>In Exchange System Manager, the <strong class=uiterm>Perform Reverse DNS Lookup for Incoming Messages</strong> option does not have the same function of the feature that had been previously described (the function to prevent the receipt of spam e-mail messages). When the preceding option is used, Exchange Server performs a DNS query to resolve the originating Internet Protocol (IP) address of the incoming messages to a host name. Then, the host name is attached to the headers of e-mail messages.<br><br>If you enable the <strong class=uiterm>Perform Reverse DNS Lookup for Incoming Messages</strong> option, you may have some performance degradation issues because of misconfigured DNS records and/or intermittent connections to the Internet. Therefore, you may want to disable this option when the Internet mail delivery is slower than expected.<br><br>By default, Exchange Server 5.5 performs a reverse lookup operation on all connections. This default operation, however, can be disabled by using a <strong>DisableReverseResolve</strong> registry setting.<br><br>For additional information, click the article numbers below to view the articles in the Microsoft Knowledge Base:
<div class=indent><a class=KBlink href="http://support.microsoft.com/kb/258745/EN-US/"><u><font color=#0000ff>258745</font></u></a><span class=pLink> (http://support.microsoft.com/kb/258745/EN-US/)</span> XIMS: Internet Mail Service Displays SMTP Banner Slowly </div>
<div class=indent><a class=KBlink href="http://support.microsoft.com/kb/198981/EN-US/"><u><font color=#0000ff>198981</font></u></a><span class=pLink> (http://support.microsoft.com/kb/198981/EN-US/)</span> XIMS: SMTP Messages Not Being Delivered to Certain Domains </div>
<div class=indent><a class=KBlink href="http://support.microsoft.com/kb/262571/EN-US/"><u><font color=#0000ff>262571</font></u></a><span class=pLink> (http://support.microsoft.com/kb/262571/EN-US/)</span> XCON: Internet Mail Service Registry Entry for DisableReverseResolve Does Not Map to Default SMTP Virtual Server After You Upgrade to Exchange 2000 </div>
</div>
</div>
<img src ="http://www.cnitblog.com/joyclear/aggbug/46692.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-14 10:34 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/14/46692.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>DNS劫持与RBL</title><link>http://www.cnitblog.com/joyclear/archive/2008/07/14/46690.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Mon, 14 Jul 2008 02:12:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/07/14/46690.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/46690.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/07/14/46690.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/46690.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/46690.html</trackback:ping><description><![CDATA[<p>最近有客户反映使用RBL后，一些不在列表里面的服务器也会被阻止，又是电信干的好事。<br>google了一下，有篇不错的技术分析文章。<br><br>作者：wxy 2008-06-10 12:35:00</p>
<div id=Content>
<p>&nbsp;　　最近接到了一些反馈说，在使用我们的RBL时，会拒绝所有入站信件。据我们判断，应该是查询者使用了具有DNS劫持的DNS服务器所导致。</p>
<p>　　首先，我们先简单说一下RBL的原理。目前用于垃圾邮件过滤的RBL服务，应该称之为基于DNS的实时黑名单查询，也就是说，这个服务是通过DNS协议来完成的。</p>
<p>　　具体而言，当一个客户端希望查询某个IP地址（如11.22.33.44）是否在某个RBL（如cbl.anti-spam.org.cn）中是，其实际上是查询如下地址是否存在解析： 44.33.22.11.cbl.anti-spam.org.cn. （IP地址逆转附加在RBL地址后）。DNS的解析分为几种类型，对于RBL查询，通常是查询这个地址是否存在A记录、TXT记录或者任意（ANY）记录。</p>
<p>　　如果该地址被列入了这个RBL，那么查询会返回一个具体的解析结果，根据RBL和查询的不同，可以返回一段文本，也可以返回一个或几个IP地址，也可以同时返回文本和IP。返回的文本通常是一个说明，用来说明这个IP地址被列入了哪个RBL，具体信息去哪里查询等。返回的IP地址并不具有实际意义，只是标识该查询有结果，通常这个IP地址是一个保留IP段的地址，如127.0.0.1、127.0.0.2等。</p>
<p>　　如果该地址没有被列入这个RBL，那么该查询会返回一个查询错误（NXDOMAIN），表示该地址未列入。DNS劫持就发生在这里，具体情况我们下面再详细解释。</p>
<p>　　举例说明这个查询过程：</p>
<p>　　当查询的IP地址不在RBL中时，返回状态为MXDOMAIN。</p>
<p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig 44.33.22.11.cbl.anti-spam.org.cn.</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; 44.33.22.11.cbl.anti-spam.org.cn.<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NXDOMAIN</font>, id: 58553<br>;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0</p>
            <p>;; QUESTION SECTION:<br>;44.33.22.11.cbl.anti-spam.org.cn. IN&nbsp;&nbsp; A</p>
            <p>;; AUTHORITY SECTION:<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 3600&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SOA&nbsp;&nbsp;&nbsp;&nbsp; cbl.anti-spam.org.cn. wxy.anti-spam.org.cn. 2008061006 14400 3600 14400 3600</p>
            <p>;; Query time: 8 msec<br>;; SERVER: 127.0.0.1#53(127.0.0.1)<br>;; WHEN: Tue Jun 10 09:28:55 2008<br>;; MSG SIZE&nbsp; rcvd: 90<br>&nbsp;</p>
            </td>
        </tr>
    </tbody>
</table>
　　当查询的IP地址在RBL中时，返回状态为NOERRO，并给出具体的结果：127.0.8.2（这里使用RBL的测试地址127.0.0.2，通常RBL都会提供一个特定地址，用于测试RBL是否工作）。</p>
<p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig 2.0.0.127.cbl.anti-spam.org.cn.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; 2.0.0.127.cbl.anti-spam.org.cn.<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NOERROR</font>, id: 5032<br>;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 6, ADDITIONAL: 0</p>
            <p>;; QUESTION SECTION:<br>;2.0.0.127.cbl.anti-spam.org.cn.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A</p>
            <p>;; ANSWER SECTION:<br><font color=#ff0000>2.0.0.127.cbl.anti-spam.org.cn. 10800 IN A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 127.0.8.2</font></p>
            <p>;; AUTHORITY SECTION:<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10800&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns1.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10800&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns3.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10800&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns4.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10800&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns5.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10800&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns7.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10800&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns8.anti-spam.org.cn.</p>
            <p>;; Query time: 3 msec<br>;; SERVER: 127.0.0.1#53(127.0.0.1)<br>;; WHEN: Tue Jun 10 09:31:01 2008<br>;; MSG SIZE&nbsp; rcvd: 172</p>
            <p>&nbsp;</p>
            </td>
        </tr>
    </tbody>
</table>
　　查询TXT记录的结果如下（通常收到由于RBL列入而退回的信件中的退信消息就是来自这里的）：</p>
<p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig 2.0.0.127.cbl.anti-spam.org.cn. TXT</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; 2.0.0.127.cbl.anti-spam.org.cn. TXT<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NOERROR</font>, id: 21173<br>;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 6, ADDITIONAL: 0</p>
            <p>;; QUESTION SECTION:<br>;2.0.0.127.cbl.anti-spam.org.cn.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TXT</p>
            <p>;; ANSWER SECTION:<br><font color=#ff0000>2.0.0.127.cbl.anti-spam.org.cn. 10800 IN TXT&nbsp;&nbsp;&nbsp; "Mail from 127.0.0.2 refused, see </font><a href="http://anti-spam.org.cn/Rbl/Query/Result?IP=127.0.0.2"><font color=#ff0000><u>http://anti-spam.org.cn/Rbl/Query/Result?IP=127.0.0.2</u></font></a><font color=#ff0000>"</font></p>
            <p>;; AUTHORITY SECTION:<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10675&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns5.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10675&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns7.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10675&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns8.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10675&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns1.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10675&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns3.anti-spam.org.cn.<br>cbl.anti-spam.org.cn.&nbsp;&nbsp; 10675&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns4.anti-spam.org.cn.</p>
            <p>;; Query time: 37 msec<br>;; SERVER: 127.0.0.1#53(127.0.0.1)<br>;; WHEN: Tue Jun 10 09:33:06 2008<br>;; MSG SIZE&nbsp; rcvd: 255</p>
            </td>
        </tr>
    </tbody>
</table>
　　在明白了RBL查询的原理后，我们来看一下RBL劫持的发生原因。</p>
<p>　　由于国内很多用户在使用电信企业的线路连接互联网时，都会使用接入的ISP所提供的DNS，有的是明确设置使用的，有的是通过PPPoE或DHCP分配使用的。最近一些年来，电信企业为了引导用户访问其增值站点或合作站点，通过会对其DNS做一些修改，在接收到一个不存在结果的DNS查询时，总是返回一些特定的IP地址，使用户访问到这些增值站点。比如你在使用ADSL上网时，如果随便在浏览器的地址栏中任意敲入一个无效的域名，通常都会给你重定向到电信企业自己的门户站点。</p>
<p>　　一般而言，这种行为对于用户没有多大的损害，最多只是扭曲了用户意志，强制其访问另外一个站点而已。但是，对于使用RBL来防范垃圾邮件的用户，这种DNS劫持就会带来较大的麻烦。在这种情况下，所有的DNS查询都会返回一个有效的结果，换言之，无论任何发来邮件的IP地址，都会被认为列入到了RBL中，用户将接收不到任何外部邮件。</p>
<p>　　那么如何应对这种情况呢？有两种办法：</p>
<p>　　<strong>一是使用一个可信的，没有被DNS劫持的DNS服务器。</strong>国内电信企业的DNS被劫持的情形比较多，尤其是做接入的ISP的DNS服务器，很多都存在劫持问题。可以考虑使用国外的公开DNS、或者一些未劫持的DNS服务器。但是要注意的是，不能使用不支持公开解析请求的DNS，即那种只解析特定域名的DNS服务器是不能用来解析其他域名的；类似的，根域服务器（*.ROOT-SERVERS.NET）也是不提供这种公开解析请求的功能的。可以通过nslookup或dig以及其它工具来测试一个DNS服务器是否可以提供公开解析功能，以及是否被劫持。</p>
<p>　　查询一个DNS服务器是否提供公开查询可以做如下测试：</p>
<p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig sina.com. @A.ROOT-SERVERS.NET.</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; sina.com. @A.ROOT-SERVERS.NET.<br>; (2 servers found)<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NOERROR</font>, id: 63123<br>;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 13, ADDITIONAL: 14</p>
            <p>;; QUESTION SECTION:<br>;sina.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A</p>
            <p>;; AUTHORITY SECTION:<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; H.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; I.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; J.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; K.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; L.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; M.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; B.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; C.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; D.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; E.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; F.GTLD-SERVERS.NET.<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; G.GTLD-SERVERS.NET.</p>
            <p>;; ADDITIONAL SECTION:<br>A.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.5.6.30<br>A.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; AAAA&nbsp;&nbsp;&nbsp; 2001:503:a83e::2:30<br>B.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.33.14.30<br>B.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; AAAA&nbsp;&nbsp;&nbsp; 2001:503:231d::2:30<br>C.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.26.92.30<br>D.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.31.80.30<br>E.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.12.94.30<br>F.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.35.51.30<br>G.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.42.93.30<br>H.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.54.112.30<br>I.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.43.172.30<br>J.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.48.79.30<br>K.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.52.178.30<br>L.GTLD-SERVERS.NET.&nbsp;&nbsp;&nbsp;&nbsp; 172800&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.41.162.30</p>
            <p>;; Query time: 267 msec<br>;; SERVER: 198.41.0.4#53(198.41.0.4)<br>;; WHEN: Tue Jun 10 09:58:33 2008<br>;; MSG SIZE&nbsp; rcvd: 498</p>
            </td>
        </tr>
    </tbody>
</table>
　　在上面这个测试中，我们使用根域服务器来查询 sina.com这个域名，返回的结果是NOERROR，但是没有ANSWER区来给出具体的IP地址。这表明该服务器（A.ROOT-SERVERS.NET.）不支持公开查询。</p>
<p>&nbsp;</p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig sina.com. @202.106.196.115&nbsp;&nbsp;&nbsp;</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; sina.com. @202.106.196.115<br>; (1 server found)<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NOERROR</font>, id: 47283<br>;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 3</p>
            <p>;; QUESTION SECTION:<br>;sina.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A</p>
            <p>;; ANSWER SECTION:<br><font color=#ff0000>sina.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1978&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 71.5.7.191</font></p>
            <p>;; AUTHORITY SECTION:<br>sina.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1976&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns1.sina.com.cn.<br>sina.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1976&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns2.sina.com.cn.<br>sina.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1976&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ns3.sina.com.cn.</p>
            <p>;; ADDITIONAL SECTION:<br>ns1.sina.com.cn.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 84804&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 202.106.184.166<br>ns2.sina.com.cn.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 84804&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 61.172.201.254<br>ns3.sina.com.cn.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 84804&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 202.108.44.55</p>
            <p>;; Query time: 2 msec<br>;; SERVER: 202.106.196.115#53(202.106.196.115)<br>;; WHEN: Tue Jun 10 11:19:13 2008<br>;; MSG SIZE&nbsp; rcvd: 155</p>
            </td>
        </tr>
    </tbody>
</table>
<p>　　在上面这个测试中，我们使用了一个公开的DNS服务器来查询sina.com 这个域名，返回了正确的解析结果。说明该服务器支持公开查询。</p>
<p>　　当使用该服务器查询一个不存在的域名时，如查询sina11111.com ：</p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig sina11111.com. @202.106.196.115</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; sina11111.com. @202.106.196.115<br>; (1 server found)<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NXDOMAIN</font>, id: 48272<br>;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0</p>
            <p>;; QUESTION SECTION:<br>;sina11111.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A</p>
            <p>;; AUTHORITY SECTION:<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 900&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SOA&nbsp;&nbsp;&nbsp;&nbsp; a.gtld-servers.net. nstld.verisign-grs.com. 1213068006 1800 900 604800 900</p>
            <p>;; Query time: 697 msec<br>;; SERVER: 202.106.196.115#53(202.106.196.115)<br>;; WHEN: Tue Jun 10 11:19:22 2008<br>;; MSG SIZE&nbsp; rcvd: 104</p>
            </td>
        </tr>
    </tbody>
</table>
<p>　　这里返回了NXDOMAIN结果，表明该服务器没有被DNS劫持。</p>
<p>　　而当我们使用了一个被劫持的DNS（在笔者测试期间还存在劫持情形）来查询一个不存在的域名：sina1234122323.com. ，查询返回结果是一个特定的IP ： 220.250.64.22 （这是一个网通的地址）。</p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr class=light>
            <td>
            <p># dig sina1234122323.com. @210.22.70.3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p>
            <p>; &lt;&lt;&gt;&gt; DiG 9.3.3rc2 &lt;&lt;&gt;&gt; sina1234122323.com. @210.22.70.3<br>; (1 server found)<br>;; global options:&nbsp; printcmd<br>;; Got answer:<br>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: <font color=#ff0000>NOERROR</font>, id: 43129<br>;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0</p>
            <p>;; QUESTION SECTION:<br>;sina1234122323.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A</p>
            <p>;; ANSWER SECTION:<br><font color=#ff0000>sina1234122323.com.&nbsp;&nbsp;&nbsp;&nbsp; 3600&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 220.250.64.22</font></p>
            <p>;; AUTHORITY SECTION:<br>com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 900&nbsp;&nbsp;&nbsp;&nbsp; IN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SOA&nbsp;&nbsp;&nbsp;&nbsp; a.gtld-servers.net. nstld.verisign-grs.com. 1213069571 1800 900 604800 900</p>
            <p>;; Query time: 2389 msec<br>;; SERVER: 210.22.70.3#53(210.22.70.3)<br>;; WHEN: Tue Jun 10 11:45:29 2008<br>;; MSG SIZE&nbsp; rcvd: 125</p>
            </td>
        </tr>
    </tbody>
</table>
<p>　　当使用该DNS查询一个存在的域名是能正确返回其IP地址。这种针对不存在的域名强制劫持到一个特定的IP的行为导致了RBL的查询返回错误。</p>
<p>　　<strong>二是对RBL查询结果进行验证。</strong>基本上所有的RBL服务都会返回特定的查询结果，即每次都返回同样的一个或几个IP地址，而且这种IP地址通常都是特定的保留IP，不会出现在正常的DNS查询中，如127.0.0.2、127.0.8.2等。目前绝大多数支持RBL查询的邮件服务器都支持对查询结果进行验证，你可以根据RBL服务所公示的查询结果来设置你的RBL查询。</p>
<p>　　本站所提供的RBL的查询验证码如下：</p>
<table cellSpacing=0 cellPadding=0 width="100%" align=center border=0>
    <tbody>
        <tr>
            <th>名称</th>
            <th>地址</th>
            <th>测试地址</th>
            <th>返回状态码</th>
        </tr>
        <tr class=light>
            <th><a href="http://www.anti-spam.org.cn/CBL"><u><font color=#0000ff>CBL</font></u></a></th>
            <td>cbl.anti-spam.org.cn</td>
            <td>2.0.0.127.cbl.anti-spam.org.cn.</td>
            <td>127.0.8.2</td>
        </tr>
        <tr class=dark>
            <th><a href="http://www.anti-spam.org.cn/CDL"><u><font color=#0000ff>CDL</font></u></a></th>
            <td>cdl.anti-spam.org.cn</td>
            <td>0.0.0.240.cdl.anti-spam.org.cn.</td>
            <td>127.0.8.4</td>
        </tr>
        <tr class=light>
            <th><a href="http://www.anti-spam.org.cn/CBL+"><u><font color=#0000ff>CBL+</font></u></a></th>
            <td>cblplus.anti-spam.org.cn</td>
            <td>2.0.0.127.cblplus.anti-spam.org.cn.</td>
            <td>127.0.8.6</td>
        </tr>
        <tr class=dark>
            <th><a href="http://www.anti-spam.org.cn/CBL-"><u><font color=#0000ff>CBL-</font></u></a></th>
            <td>cblless.anti-spam.org.cn</td>
            <td>2.0.0.127.cblless.anti-spam.org.cn.</td>
            <td>127.0.8.5</td>
        </tr>
    </tbody>
</table>
<p>　　因此，鉴于国内DNS劫持的情形日益严重，在使用RBL服务时，要确认自己的DNS是否存在劫持；而且最好设置验证码，这样即便DNS当时未被劫持，将来发生了劫持也不会影响到邮件服务。</p>
</div>
<img src ="http://www.cnitblog.com/joyclear/aggbug/46690.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-07-14 10:12 <a href="http://www.cnitblog.com/joyclear/archive/2008/07/14/46690.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>OWA访问重定向</title><link>http://www.cnitblog.com/joyclear/archive/2008/06/26/45999.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Thu, 26 Jun 2008 10:00:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/06/26/45999.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/45999.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/06/26/45999.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/45999.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/45999.html</trackback:ping><description><![CDATA[<strong>HTTPS访问方式重定向</strong><br>
<ol>
    <li>
    <p>打开 IIS 管理器，然后导航到&#8220;网站/默认网站&#8221;<strong><!----></strong>。右键单击&#8220;默认网站&#8221;<strong><!----></strong>，然后单击&#8220;属性&#8221;<strong><!----></strong>。</p>
    <li>
    <p>单击&#8220;主目录&#8221;<strong><!----></strong>选项卡，然后单击&#8220;重定向到 URL&#8221;<strong><!----></strong>选项。</p>
    <li>
    <p>在&#8220;重定向到&#8221;<strong><!----></strong>中，键入 /<em>目录名称</em>。例如，若要将 https://<em>服务器名称</em> 请求重定向到 https://<em>服务器名称</em>/exchange，请在&#8220;重定向到&#8221;<strong><!----></strong>中键入 /<strong>exchange</strong>。</p>
    <ul>
        <li>如果将使用 Outlook&nbsp;Web&nbsp;Access 访问的所有邮箱均位于 Exchange&nbsp;2007 服务器上，可以将 /<strong>exchange</strong> 替换为 /<strong>owa</strong>。这样可以将所有 https://<em>服务器名称</em> 请求重定向到 https://servername/owa。<br></li>
    </ul>
    <li>
    <p>在&#8220;客户端将定向到:&#8221;<strong><!----></strong>列表中，选择&#8220;输入的 URL 下的目录&#8221;<strong><!----></strong>。</p>
    </li>
</ol>
<p><strong>HTTP访问方式重定向到HTTPS</strong><br></p>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 1.&nbsp; 在记事本中创建以下文件，并将其保存为 <em>驱动器</em>:\inetpub\wwwroot 下的 SLRedirect.htm，将 <em>&lt;服务器名称&gt;</em> 替换为您的客户端访问服务器的名称：<br>&lt;html&gt;<br>&lt;head&gt;<br>&lt;title&gt;HTML Redirection to https:&lt;/title&gt;<br>&lt;META HTTP-EQUIV="Refresh"<br>CONTENT="1; URL=https://&lt;servername&gt;/exchange"&gt;<br>&lt;/head&gt;<br>&lt;body&gt;<br>This page is attempting to redirect you to &lt;a href="https:// &lt;servername&gt;/exchange/"&gt;https:// &lt;servername&gt;/exchange&lt;/a&gt;&lt;br&gt;<br>If you are not redirected within a few seconds, please click the link above to access Outlook Web Access.<br>&lt;/body&gt;&lt;/html&gt;<br></div>
<ol>
    <li>
    <p>打开 IIS 管理器，然后导航到&#8220;网站/默认网站&#8221;<strong><!----></strong>。右键单击&#8220;默认网站&#8221;<strong><!----></strong>，然后单击&#8220;属性&#8221;<strong><!----></strong>。</p>
    <li>
    <p>单击&#8220;主目录&#8221;<strong><!----></strong>选项卡，然后选择&#8220;重定向到 URL&#8221;<strong><!----></strong>。</p>
    <li>
    <p>在&#8220;重定向到&#8221;<strong><!----></strong>中输入 /<strong>Exchange</strong>。</p>
    <li>
    <p>选择&#8220;客户端将定向到: 输入的 URL 下的目录&#8221;<strong><!----></strong>。</p>
    <li>
    <p>单击&#8220;自定义错误&#8221;<strong><!----></strong>选项卡，然后在表中找到 HTTP 错误 403;4。通过单击选中 <strong>403;4</strong>，然后单击&#8220;编辑&#8221;<strong><!----></strong>。</p>
    <li>
    <p>单击&#8220;浏览&#8221;<strong><!----></strong>找到此步骤开始时创建的文件。</p>
    <li>
    <p>单击&#8220;确定&#8221;<strong><!----></strong>保存更改。</p>
    <li>
    <p>打开命令提示符窗口，然后键入 <strong>iisreset /noforce</strong> 以重新启动 IIS</p>
    </li>
</ol>
<img src ="http://www.cnitblog.com/joyclear/aggbug/45999.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-06-26 18:00 <a href="http://www.cnitblog.com/joyclear/archive/2008/06/26/45999.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Exchange 2007占用大量系统内存</title><link>http://www.cnitblog.com/joyclear/archive/2008/06/24/45955.html</link><dc:creator>joyclear</dc:creator><author>joyclear</author><pubDate>Tue, 24 Jun 2008 03:13:00 GMT</pubDate><guid>http://www.cnitblog.com/joyclear/archive/2008/06/24/45955.html</guid><wfw:comment>http://www.cnitblog.com/joyclear/comments/45955.html</wfw:comment><comments>http://www.cnitblog.com/joyclear/archive/2008/06/24/45955.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/joyclear/comments/commentRss/45955.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/joyclear/services/trackbacks/45955.html</trackback:ping><description><![CDATA[Exchange 2007启动后Store会占用大量的内存，下面是微软工程师和技术专家的解答<br><span><font face=Arial size=2>&nbsp;
<p><font face=宋体><span>您好！</span></font></p>
<p>&nbsp;<font face=宋体><span>感谢您的回复！</span></font></p>
<p>&nbsp;<span><font face=宋体>根据您的截图和日志信息，这种现象是正常的。下面我解释一下其中的原因，在</font></span><span>Exchange 2003</span><span><font face=宋体>中，</font></span><span>store.exe</span><span><font face=宋体>进程使用的内存被限制在某个特定的值。在默认情况下，该值为</font></span><span>900MB</span><font face=宋体><span>左右。</span></font></p>
<p>&nbsp;<span><font face=宋体>在</font></span><span>Exchange 2007</span><span><font face=宋体>中，由于硬件基于</font></span><span>64</span><span><font face=宋体>位，对数据库缓存大小的限制已经不存在了，因此</font></span><span>store.exe </span><span><font face=宋体>进程将不在被限制在</font></span><span>900MB</span><span><font face=宋体>。当前，</font></span><span>Exchange 2007</span><span><font face=宋体>默认的最小的缓存值为</font></span><span>512MB</span><span><font face=宋体>（计算机必须至少有</font></span><span>2G</span><span><font face=宋体>的内存），并且没有最大值的限制，也就是说，</font></span><span>ESE (store.exe)</span><span><font face=宋体>将增加该缓存值来消耗掉服务器上所有几乎可用的内存，在系统没有内存压力的情况下，这将大大地增加数据库缓存大小，并显著地减少磁盘</font></span><span>I/O</span><span><font face=宋体>，并且数据库缓存是首先的，因为从内存中读取信息比从磁盘中要快的多，如果内存压力出现，当其他应用程序请求内存，</font></span><span>ESE</span><font face=宋体><span>将自动缩小它的数据库缓存值。</span></font></p>
<p>&nbsp;<span><font face=宋体>例如，如果服务器有</font></span><span>16G</span><span><font face=宋体>的物理内存，如果没有其他内存压力的话，</font></span><span>store.exe </span><span><font face=宋体>将使用</font></span><span>14GB</span><span><font face=宋体>的内存（其中有</font></span><span>2GB</span><span><font face=宋体>分配给</font></span><span>Kernel mode</span><font face=宋体><span>）</span></font></p>
<p>&nbsp;<font face=宋体><span>谢谢！</span></font></p>
<p>&nbsp;<span>Rock Wang </span><span><font face=宋体>望正茂<br><br></p>
<p align=left>Although i haven't read your log or reports, however, it seems very normal to me that your Exchange is 'eating' up your memory. </p>
<p align=left>This is actually by-design from Exchange 2000's ESE engine (store.exe). The ESE engine will utilize your system memory dynamically based on the phsyical memory installed.&nbsp;In very typical situation, i've seen a 14G size being utilized by the store.exe on a 16G box.&nbsp;Generally,&nbsp;database cache&nbsp;typically results in&nbsp;reduced disk I/O, however, if your store.exe is not utilizing the memory as you wish, you can change its behaviour by playing with the ADSIEDIT tool.</p>
<p align=left>Generally, open up your adsiedit, and navigate to Configuration &gt; Services &gt; Microsoft Exchange &gt; Exchange organization &gt; AdministrativeGroups &gt; Your administrative group &gt; Servers &gt; Server name &gt; Information Store.</p>
<p align=left>Right-click Informatio Store and select Properties.</p>
<p align=left>Scroll and locate the msExchESEParamCacheSizeMax.</p>
<p align=left>if you want to hard limit the store.exe process to only reserve up to 10G of size, do the following calculation:</p>
<p align=left>(1024*10*1024) / 8 = 1310720</p>
<p align=left>say, if you want to limit down to 14G, then..</p>
<p align=left>(1024*14*1024) / 8 = 1835008</p>
<p>&nbsp;last, please ensure your result is an exact multiple of 8192 for maximum efficiency, if not, the server won't crash, but partial memory will be wasted.</p>
<p>do a quick search&nbsp;for msExchESEParamCacheSizeMax&nbsp;on live.com and you'll find many practical examples.</p>
<p align=left>Its that easy!</p>
<p align=left>Howard Chow.</p>
</font></span>
<p align=left></font></span></p>
<img src ="http://www.cnitblog.com/joyclear/aggbug/45955.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/joyclear/" target="_blank">joyclear</a> 2008-06-24 11:13 <a href="http://www.cnitblog.com/joyclear/archive/2008/06/24/45955.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>