Sign in
Van's FSS/Antigen/FOPE Blog
My Blog for all Antigen/Forefront Server and Forefront Online Protection for Exchange issues
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
Antigen
Antigen Upgrade
Anti-Spam
Cluster
Engine issues
Engine Updates
Forefront
Forefront for Exchange
Forefront Server Security
Install
Performance
Upgrade
x64
Archive
Archives
August 2012
(2)
April 2012
(2)
December 2011
(1)
September 2011
(1)
June 2011
(2)
May 2011
(2)
April 2011
(1)
March 2011
(1)
February 2011
(1)
December 2010
(1)
September 2010
(2)
June 2010
(1)
May 2010
(1)
April 2010
(2)
February 2010
(1)
December 2009
(1)
November 2009
(2)
October 2009
(1)
September 2009
(4)
August 2009
(4)
July 2009
(3)
June 2009
(4)
May 2009
(2)
TechNet Blogs
>
Van's FSS/Antigen/FOPE Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Van's FSS/Antigen/FOPE Blog
Microsoft Scan engine failing to update
Posted
9 months ago
by
Van Makriniotis-CSS Security
8
Comments
Just as a heads up. We are seeing cases where the Microsoft scan engine is failing to update in Forefront Protection for Exchange with the following errors. 6019 GetEngineFiles An error occurred while testing the scan engine. 6012 GetEngineFiles An error...
Van's FSS/Antigen/FOPE Blog
FOPE–Configuration and SPF checking
Posted
9 months ago
by
Van Makriniotis-CSS Security
1
Comments
We are in the process of adding this information to our setup documents. -When implementing FOPE or O365/Live@EDU and you have mail coming to your on premise servers, you need to turn off any SPF checking at your mail server/firewall. The connecting...
Van's FSS/Antigen/FOPE Blog
Hello Fope!
Posted
over 1 year ago
by
Van Makriniotis-CSS Security
0
Comments
My first FOPE centered blog. One common issue with FOPE (this also happens in FSS/Antigen) is the 0 day Virus’s that pretend to be a legitimate mail from other senders. These tend to be small emails asking you to open the file in a zip attached to the...
Van's FSS/Antigen/FOPE Blog
FSSMC/FPFMC Error 500 when launching
Posted
over 1 year ago
by
Van Makriniotis-CSS Security
0
Comments
If you have issues logging into any of the Forefront Management Consoles with an Error 500 you most likely changed the service account password. To verify this is due to a password issue you can check the event logs for Event ID 10004, Distributed COM...
Van's FSS/Antigen/FOPE Blog
FPE issue where all spam is missed
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
0
Comments
The most common reason we do not filter spam in FPE is that we honor the ms-exch-bypass-anti-spam permission on connectors. The most common scenario is that the bypass is enabled for anonymous connections. This is simple to fix with some PowerShell commands...
Van's FSS/Antigen/FOPE Blog
Resolved – Engine update issue seen on multiple servers 09/22
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
4
Comments
Updates to this issue will be posted to http://blogs.technet.com/b/fss/ Last night we pushed out an update that resolves this issue. Updating your engines should resolve this issue and you can go back to your previous configuration.
Van's FSS/Antigen/FOPE Blog
Antigen 9.x Update issue.
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
2
Comments
During our testing we have discovered that there is a potential to download the Cloudmark engine update even when there is not an update. This is being looked at but for now it is recommended that you set Cloudmark to update only every 24 hours to avoid...
Van's FSS/Antigen/FOPE Blog
Cloudmark and Antigen 9.x issues on the weekend of 06/25/11
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
13
Comments
*Updated to include default folder path for Cloudmark* If you are having issues with timeouts after updating your Cloudmark engine between Friday and Saturday afternoon this post should help you out. On Friday night we released a Cloudmark engine...
Van's FSS/Antigen/FOPE Blog
Keep an eye out for Kaspersky Not updating
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
2
Comments
We have been seeing some Antigen 9.x servers up past rollup-3 that are still not updating to Kaspersky 8. As of last week, customers still running Kaspersky5 started getting errors during attempted updates. This is normally due to one or more files being...
Van's FSS/Antigen/FOPE Blog
Strange Configurations and how they impact your servers.
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
0
Comments
We have had a few strange detection issues last week due to some non-standard configurations. 1. Spam filtering not working for User X This one was due to a setting in content filtering. There is a setting called AntispamBypassEnabled for each user...
Van's FSS/Antigen/FOPE Blog
FSEMailPickup service does not start after applying Rollup 4
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
0
Comments
This issue is starting to pop up in a few environments with connectivity issues to https:\\crl.microsoft.com It looks like we implemented code access security into our Mail Pickup service. The issue is some firewalls or proxies might not allow this site...
Van's FSS/Antigen/FOPE Blog
Forefront fore SharePoint \ Exchange Compressed File Size settings
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
0
Comments
I get these issues every few months. SharePoint or Exchange Admin getting files deleted due to Large uncompressed size or large compressed size virus. We have a few KB’s on this but there is some detail that is missing. I also realized today that...
Van's FSS/Antigen/FOPE Blog
Intermittent download failures
Posted
over 2 years ago
by
Van Makriniotis-CSS Security
0
Comments
Just wanted to give everyone a heads up. Some customers are reporting a failure (less than 5% of the time) downloading engines. The next time a download occurs it will download just fine. We are looking into the cause and the fix will be automatic as...
Van's FSS/Antigen/FOPE Blog
FPE and Online Protection–Not scanning mail that has been scanned by FOPE
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
0
Comments
There has been some major confusion on the setting under advanced options in Forefront Protection for exchange called “Rescan messages already scanned by Forefront Online protection for Exchange” By default it looks like this Now this looks like...
Van's FSS/Antigen/FOPE Blog
Norman engine issue since the 9th of September 2010 on Forefront Protection for Exchange Server
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
0
Comments
We are tracking an issue where Norman updates on Forefront Protection for Exchange are failing with a version downloaded is older than the local version message. Event ID 6014, Source GetEngineFiles. The workaround for this issue is to delete the numbered...
Van's FSS/Antigen/FOPE Blog
Worm w32/vb.wf out in the wild.
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
0
Comments
Information and links on this wiki page. http://social.technet.microsoft.com/wiki/contents/articles/worm-win32-vb-wf-forefront-and-antigen-mitigation.aspx This is spreading quickly. I expect that most Antigen users are already filtering but if you have...
Van's FSS/Antigen/FOPE Blog
Forefront protection manager Spam configuration
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
0
Comments
I had a question on how we can change the default action for spam to allow end users to manage what is spam and is not spam. In AntiSpam configuration under policy management By default our settings are quarantine at SCL 5-8 and reject at SCL 9. To allow...
Van's FSS/Antigen/FOPE Blog
Issue of the week: FPE\Antigen\FSS file type filtering
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
1
Comments
I decided to write up a filter guide as there seems to be some confusion with the new interface in FPE. The screens are from FPE but the guidance is good for filtering in all of our products. With Forefront Protection for Exchange we have drastically...
Van's FSS/Antigen/FOPE Blog
Forefront protection for exchange blocks Outlook block sender functionality and Exchange IMF
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
2
Comments
I would recommend FPE customers do this. By default when our Anti-spam agent finds something as clean we mark it SCL -1 This can cause a lot of issues with Exchange Blocked senders and it also blocks out any chance of IMF catching something. This is covered...
Van's FSS/Antigen/FOPE Blog
Mytob/mydoom Filtering
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
0
Comments
Mytob and mydoom variants seem to be on the rise in the last week. These files are named in a way to fool users into thinking the file is something other than an executable. in this example a quick look at the file in postcard.zip might make you think...
Van's FSS/Antigen/FOPE Blog
Forefront Management console template deployment
Posted
over 3 years ago
by
Van Makriniotis-CSS Security
0
Comments
Forefront Management console (FSSMC) has various jobs for configuring your server. The main job is the general options settings. This configures items in general options for Antigen/forefront servers. Other settings such as filter lists, scan engine...
Van's FSS/Antigen/FOPE Blog
Issue with SP2 for Antigen for exchange
Posted
over 4 years ago
by
Van Makriniotis-CSS Security
2
Comments
We are seeing a few calls from people that have upgraded to Antigen for Exchange SP2. These calls have AntigenService.exe hanging. This can create issues updating, connecting with the client and mail flow issues. This issue is caused when we initialize...
Van's FSS/Antigen/FOPE Blog
If you are updating to SP2
Posted
over 4 years ago
by
Van Makriniotis-CSS Security
0
Comments
make sure your engines have updated after October. SP2 has a mapper (packaged with the engines) requirement that was released two months before SP2 came out. we have seen a case that had a customer not updating for a year and this caused the engines to...
Van's FSS/Antigen/FOPE Blog
10 days till engine deprecation
Posted
over 4 years ago
by
Van Makriniotis-CSS Security
0
Comments
If you have written into support lately you should have seen something like this in the signature of the engineer you were working with Did you know Antigen and Forefront will be removing support for the CA, Sophos, AhnLab and SpamCure engines...
Van's FSS/Antigen/FOPE Blog
Issue of the week 10/9/09 - StatisticsManagerServer event id 100
Posted
over 4 years ago
by
Van Makriniotis-CSS Security
0
Comments
Issue: Constant StatisticsManagerServer event id 100 on the passive node of a 2003 cluster (maybe on a SCC cluster in 2008 as well) Cause: Antigen Statistics Service needs to access the statistics.xml located in the %data% folder of the Antigen...
Page 1 of 2 (42 items)
1
2