Information and notes Fast Channel version
WARNING: Make sure you have installed version 15.7.0.3377 first before updating to version 16. Updating from a different version may cause problems.
System requirements
General requirements
Information on the system requirements can be found in the online documentation.
NoSpamProxy
- Windows Server 2019 or later
- Microsoft SQL Server Standard/Enterprise 2016 Service Pack 1 or Microsoft SQL Express 2025 (on Windows Server 2019 or later).
- How to update SQL Server can be found on the Microsoft Website.
- Microsoft .NET Framework 4.8
Gatewayrolle
- Working DNS resolution. This is used by NoSpamProxy Protection for resolving Realtime Blocklists and Spam URL Blocklists. NoSpamProxy Encryption requires DNS resolution for certificate verification (access to ‘Certificate Revocation Lists’ and ‘OCSP’).
- HTTP, HTTPS and LDAP access to the Internet. NoSpamProxy Protection requires access for one of the real-time blocklists, the Core Antispam Engine and the Integrated Malware Scanner. NoSpamProxy Encryption uses HTTP and HTTPS as well as LDAP for certificate checking (access to ‘Certificate Revocation Lists’ and ‘OCSP’ ).
- If a firewall is used, appropriate port releases for all ports intended for NoSpamProxy (usually this is port 25).
- TCP connection via port 6060 and HTTPS connection via port 6062 from the interface to the Gateway Role. These ports are needed for the initial connection setup between Gateway Roles and the Intranet Role. After all Gateway Roles are connected, communication to them is done only via the Intranet Role.
- Optional: Any file-based on-access virus scanner.
- Access to nimbus.bitdefender.net.
Intranet Role
- TCP connection via port 6060 and HTTPS connection via port 6061 from interface to the Intranet Role
- TCP connection via port 6060 and HTTPS connection via port 6062 from Intranet Role to the Gateway Role
- Optional: TCP connection to a Domain Controller via LDAP or Global Catalog
- Optional: TCP connection to the Web Portal via HTTPS.
NoSpamProxy Command Center
- TCP connection via port 6060 and HTTPS connection via port 6061 from interface to Intranet Role
Outlook Add-In
Information on the requirements for the Outlook Add-In can be found in the online documentation.
Web Portal
- Windows Server 2019 or later
- Microsoft .NET Framework 4.8
- Microsoft SQL Server Standard/Enterprise 2016 Service Pack 1 or Microsoft SQL Express 2025.
Preparations
Depending on the planned installation environment, different preparations are necessary.
- If you use a firewall, the port intended for the NoSpamProxy Web Portal must be open. Usually this is port 443.
- If the IIS are installed on the same system as one of the Gateway Roles, disable SSL loopback checking. The procedure is described in the Microsoft Knowledge Base.
- Use method 1 to set up an exception for the connection to this address.
- Method 2 is not recommended as it would disable an essential security feature of your server.
- If the Web Portal is installed on a computer in the DMZ or on a computer outside the domain, please disable the UAC remote restrictions. The procedure is described in the Microsoft Knowledge Base.
Starting the update
Before updating
- Verify that the version of Microsoft SQL Server Standard/Enterprise or Microsoft SQL Express you are using is up to date.
- When updating Microsoft SQL Server or Microsoft SQL Server Express, stop all NoSpamProxy services that access it to avoid database inconsistencies.
- Due to more precise file type detection, it may be necessary to adjust existing settings in the content filter. With the new detection, file types are assigned more accurately. As a result, existing filter rules may no longer function as expected. If your filter rules specifically target certain MIME types, we recommend reviewing them and adjusting them as necessary. A complete list of all recognized file formats can be found in the online documentation.
- If you use an allowlist approach for content filtering, proceed as follows:
-
- Remove the “Reject All” rule before the update.
- Perform the update.
- Check the content filter and verify the file types.
- Enable the “Reject All” rule.
- Please note that the “new” TCP proxy is now mandatory. The “old” TCP proxy, which had to be enabled via the configuration file, is no longer supported. For more information on the TCP proxy, please refer to the online documentation.
Sequence for updating
- Update the Intranet Role. This may take some time. A temporary increase in the allocated RAM may be helpful.
- Update the Gateway Role(s). If you are using multiple Gateway Roles, update them one at a time.
- Update the Web Portal.
Starting the Update
Click the NoSpamProxy setup file. The wizard will guide you through the installation of the new version.
Changes and recommendations
Content Filter MIME Types
Due to more precise file type detection, it may be necessary to adjust existing settings in the content filter. With the new detection, file types are classified more accurately. As a result, existing filter rules may no longer function as expected. If your filter rules are specifically targeted at certain MIME types, we recommend that you review them and adjust them as necessary. A complete list of all recognized file formats can be found in the online documentation.
New TCP Proxy
Please note that the “new” TCP proxy is now mandatory. The “old” TCP proxy, which had to be activated via the configuration file, is no longer supported. For more information on the TCP proxy, please refer to the online documentation.
DMARC Check for “p=none”
It is now possible to reject emails that fail DMARC validation, even when the DMARC policy is set to p=none.
