Exchange 2016 - Multiple receive connectors with same IP&port bindings, but different authentications?

Dave Bryan 96 Reputation points
2021-01-08T17:07:25.74+00:00

I am upgrading from Exchange 2010 to 2016(hybrid for O365) and trying to add in new receive connectors that allow specific Internal server IPs to relay mail with different levels of authentications and same Exchange server IP binding and ports(25), but this does not seem to be an option with 2016 like I have with 2010. I have some servers that relay mail with certain levels of authentication and other copier/scanners that might have no authentication, etc. It seems to want to force me to use a different IP or different port, or the default one, and then make changes to authentication methods of all SMTP traffic flowing through it. Does anyone know if this is still possible?

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,356 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,895 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Ashok M 6,506 Reputation points
    2021-01-10T09:27:42.047+00:00

    Hi @Dave Bryan ,

    Based on my understanding, you can create multiple custom receive connector for the same Exchange server for Application relay. Each connector will be differentiated based on the remote IP addresses and Authentication. While creating receive connector, you have to select Role as "FrontEndTransport" and Type as "Custom"

    https://learn.microsoft.com/en-us/exchange/mail-flow/connectors/receive-connectors?view=exchserver-2016#receive-connector-remote-addresses

    If the above suggestion helps, please click on "Accept Answer" and upvote it

    0 comments No comments

  2. Kael Yao-MSFT 37,496 Reputation points Microsoft Vendor
    2021-01-11T02:06:55.63+00:00

    @Dave Bryan
    Hi,

    Agree with Ashok, it is possible.

    As is mentioned in the document: Receive connectors
    55098-66.png
    Though all the receive connectors listen on port 25 of the Exchange server, since the source addresses vary from each other, the most matched connectors will be used.

    After you created the receive connectors, you can configure the authentication settings via editing the connectors:
    55161-67.png


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  3. Dave Bryan 96 Reputation points
    2021-01-11T12:56:52.85+00:00

    Thanks for all of the responses guys. Exchange will not let you add the new connector with the same bindings without getting this error

    The values that you specified for the Bindings and RemoteIPRanges parameters conflict with the settings on Receive connector "EXSRV2016\Default Frontend EXSRV2016". Receive connectors assigned to different Transport roles on a single server must listen on unique local IP address & port bindings.