Windows EventLog 1035 --> Default Frontend MailServer

MikeZetPL 21 Reputation points
2023-01-09T10:31:37.763+00:00

Hello.
In my small company we use single Exchange 2016 CU23 Server [>100 users].
Since some days I'm facing with receive many errors in Windows EventLog 1035 from Default Frontend
MailServer:
277367-eventlog.png
After check many Exchange logs I found some interesting part in FrontendTransport --> SmtpReceive logs when this log in WinEventLog is registred in the same time. Part of this exchange log is here:
277412-default-frontend-log.txt
My all receive connectors are:
277413-receiveconnectors-all.png
Security of my Default Frontend MailServer looks like this:
277398-receiveconnectorconf-sec.png
So my main questions for this topic are:

  1. Can this somehow avoided with better config of Default Frontend receive connector?
  2. Or rather is an security issue and communication need to be better protect for example on external firewall?
Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,350 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,686 questions
0 comments No comments
{count} votes

Accepted answer
  1. Kael Yao-MSFT 37,651 Reputation points Microsoft Vendor
    2023-01-10T02:09:35.18+00:00

    Hi @MikeZetPL

    Can this somehow avoided with better config of Default Frontend receive connector?

    It is not recommended to modify the settings of the five default receive connectors (including the Default Frontend receive connector).
    I would suggest just leave it as the default setting to avoid issues.

    Or rather is an security issue and communication need to be better protect for example on external firewall?

    To me this may seem like probes or script attacks.
    If you have found a large amount of suspicious requests from some specific ip addresses, please consider blocking these ip addresses on your firewall.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.