If we do not provision any users on the secondary, I assume this transfers the load for all spam to the primary, correct? I'm wondering if this method is less effective at catching spam than having all the users setup on the secondary? Our current system (qmail+assp) fails miserably if the secondary does not have a similar anti-spam setup.
As far as cutting down on spam through the secondary (not that the users would see, but that affects server load and traffic):
You can provision all users on the secondary itself, then set the ZimbraMailTransport on each account individually. Just have to remember to maintain both places.