Hello All,
I have an issue with one particular e-newsletter that needs to come into our network, but is being dropped for some reason.
The incoming email trajectory is:
A Cisco 2811 as our border router
Nokia IP 1220 Firewall
Sophos ES1000 Email Filter
(The transmission does not get this far. However, we have:)
SurfControl Content Filter
Exchange 2003 Front End
Exchange 2003 Back End
I have pored over our border router and Firewall logs and we can see the smtp conversations for this particular email being green-lighted and passing through.
I've also been working with the Sophos tech and he can see the following in the appliance logs.
Feb 11 TZMA01 postfix/smtpd[53381]: timeout after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[53381]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54383]: timeout after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54383]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[52946]: timeout after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[52946]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54376]: timeout after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54376]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54409]: connect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54409]: D1E4B2220241: client=external.mail.com[2
03.xxx.xxx
.xxx]
Feb 11 TZMA01 postfix/smtpd[54409]: lost connection after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54409]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54508]: timeout after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[54508]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[69227]: connect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[69227]: BB12122202C8: client=external.mail.com[2
03.xxx.xxx
.xxx]
Feb 11 TZMA01 postfix/smtpd[69227]: lost connection after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[69227]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[53226]: timeout after DATA from external.mail.com[203.xxx.
xxx.xxx]
Feb 11 TZMA01 postfix/smtpd[53226]: disconnect from external.mail.com[203.xxx.
xxx.xxx]
However, he cannot give me a reason for the disconnection.
The appliance itself is not registering the email spam (as yet) because it does not look as though the SMTP communication is finishing successfully.
By running a sniffer over the connection we can see pretty much the whole email come through, apart from the last few expected packets and the all important <.> end transmission sequence.
Our next testing step is to bypass Sophos and Surfcontrol altogether and go straight to the Exchange FE. This will only be for a very short time in order to test the extent of this particular issue (and mitigate risks).
Also, our MTU size is currently set to 1492. I will probably test setting this to 1500 and see if it works.
Has anyone seen these symptoms before?
Any assistance would be appreciated as I have exhausted all options from my end.
Thanks in advance.
Joe
Start Free Trial