Question

Mail stuck in queues on exchange 2007 hub and edge transport server

Asked by: biggles70

Well it's late and unfortunately we have been trying to get this problem sorted with no luck.

Basically we have transitioned from a Windows 2000 Exchange 2000 to Windows 2008 SP1 with Exchange 2007 SP1 with an Edge server in the DMZ as well.  The problem we are seeing is that mail messages are queuing up on the hub server and also inbound messages are queuing up on the edge transport server. The problem is getting the message from the hub to the edge and vice versa.

We have been playing around with connectors without luck and we are able to telnet to port 25 on both the hub server and edge transport server no problems.  When we run a forced sync it works and a test succeeds as well.

On the exchange hub server we get the following error in the Queue Viewer:
451 4.4.0 Primary target IP address responded with: "421 4.4.1 Connection timed out."

On the Edge transport server we get the error message as follows:
451 4.4.0 Primary target IP address responded with: "451 5.7.3 Cannot achieve Exchange Server authentication      

Anyway I am hoping that someone out there can shed some light on this one.  we have been looking all over the web, it has been a really long couple of days and any info would be appreciated.

Thanks.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-07-26 at 06:07:18ID24601016
Tags

Microsoft exchange server 2007 edge transport server

Topics

Exchange Email Server

,

Windows Server 2008

Participating Experts
3
Points
0
Comments
13

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Messages awaiting directory lookup - Email Queuing
    Messages are queuing in the "Messages awaiting directory lookup" queue. General Configuration information: Exchange 2003 SP 1 Server A Internet Mail Connector 1 configured as a Smart Host to DMZ Server A (IIS 6.0 SMTP Gateway) with a cost of (1) (4) 2.0 GHz Pro...
  2. SMTP Connector QUeue
    Experts, On my Exchange system manager, i went to the server and queue. i see two of our smtp connectors have 1 msgg waiting the status is set to "retry" and the mssage has been there for a while, on both smtp connectors. I tried a force connection and unfreeze ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: demazterPosted on 2009-07-26 at 06:12:50ID: 24945611

 

by: renazonsePosted on 2009-07-26 at 06:32:15ID: 24945691

under your receive connectors authentication tab, is Exchange and Integrated Windows authentication checked? They need to be.

 

by: demazterPosted on 2009-07-26 at 06:33:11ID: 24945699

Which is what it says in the thread I posted.

 

by: renazonsePosted on 2009-07-26 at 06:46:18ID: 24945750

What are the settings for your Send Connector on your Edge server?

This article explains exactly how to configure your connectors for the Edge Server and HUB : http://technet.microsoft.com/en-us/library/bb123883.aspx

@ Connector Configuration
In Exchange 2007, Receive connectors represent an inbound connection point for Simple Mail Transfer Protocol (SMTP) communications. Send connectors represent a logical gateway through which all outbound messages are sent. For end-to-end mail flow, the Edge Transport server must have connectors that support mail flow to and from the Internet, and to and from the organization. The following connectors are required on the Edge Transport server:

    * A Send connector that is configured to send messages to the Internet
      The address space for this connector is typically "*" (all Internet domains) and DNS routing is used to resolve destinations. The usage type for this connector is Internet. This Send connector is created automatically when the Edge Transport server is subscribed to an Active Directory directory service site by using EdgeSync.
    * A Receive connector that is configured to accept messages from the Internet
      This connector typically accepts connections from all IP address ranges and allows for anonymous access. The local network bindings for this Receive connector should be the external-facing IP address of the Edge Transport server. The usage type for this connector is Internet.
    * A Send connector that is configured to send messages to the Hub Transport servers in the Exchange organization
      The address space for this connector can be "--", or you can list each of your accepted domains. Use the Hub Transport servers in the organization as the smart hosts for this connector. The usage type for this connector is Internal. This Send connector is created automatically when the Edge Transport server is subscribed to an Active Directory site by using EdgeSync.
    * A Receive connector that is configured to receive messages from Hub Transport servers in the Exchange organization
      This connector can be configured to accept connections only from the IP address ranges assigned to the Hub Transport servers. The local network bindings for this Receive connector should be the internal-facing IP address of the Edge Transport server. The usage type for this connector is Internal. This connector is optional.

@demazter - sorry about that...I don't follow all the links posted in a thread.

 

by: shauncroucherPosted on 2009-07-26 at 06:54:58ID: 24945786

You should need to do anything with the EdgeSync Send/Receive connectors, they should work fine out the box.

I would recommend you scrap the Edge Subscription on Hub --> Org config --> Edge Subscriptions, go to Edge, recreate the Edge File and then import on Hub, and ensure you have 'Create Send Connector' ticked. This will recreate the connectors with the correct settings.

Start-EdgeSyncronization and Test-E... from Hub,

Clear the queues down if necessary and test with an inbound and outbound email from mailbox user to outside and vice versa.

Shaun

 

by: shauncroucherPosted on 2009-07-26 at 07:02:30ID: 24945808

 

by: shauncroucherPosted on 2009-07-26 at 08:39:10ID: 24946245

Just going through some recent articles that have been written and I come across one that describes the process of commissioning an Edge Server without using EdgeSync (for times when it is not possible to use EdgeSync.

This may come in handy, if you cannot use EdgeSync, or the process fails for whatever reason.

http://www.msexchange.org/articles_tutorials/exchange-server-2007/security-message-hygiene/configuring-edge-transport-server-without-edge-synchronization-part1.html

Shaun

 

by: biggles70Posted on 2009-07-26 at 19:09:39ID: 24948480

Hi All,

Thanks very much for the responses that are coming through - greatly appreciated.  I thought I would put in a bit more details as to what we have done to date.

With relation to deleting the Edge subscription and recreating it, we have done this about 5 times in total with the same result each time.  After rereating and importing the Edge Subscription we are able to run Start-EdgeSynchronization and also Test-Edge.... both of these work fine and the appropriate connectors are being created also.  I guess it is good to know that we can install the Edge server without the need for EdgeSync, however I'm not so sure that this is the problem seeing as though the sync works and test fine as well.

We've also read a few of the articles about the Edge server at www.msexchange.org, and in fact had the 6 part epic on hand when installing - what a great site that is.

It looks like the other connectors all work fine as messages are queued up in the Hub for outbound and Edge server for inbound.  All in all it seems to be all about getting messages to travel back and forth between the 2 even though the sync and test sync works fine - this is what seems weird.  We can also telnet from each to the other using FQDN on port 25 - if this is the case can we rule out DNS or is there something else in there that could be causing problems?  

We have the 2 networks internal and DMZ.  The Hub server uses a DNS server on the internal network, whilst there is a seperate DNS that the edge server uses.

Below is a bit of a layout of how things stand at present with DNS:

Internal Network
Exchange Server: exchange.internal.com (now has edge.dmz.com in hosts file)
DNS Server: dns.internal.com
                    Has a forward lookup zone for dmz.com and also has a record for edge.dmz.com

DMZ Network
Edge Server: edge.dmz.com (now has exchange.internal.com in the hosts file)
DNS Server: dns.dmz.com - used by edge.dmz.com has entry for exchange.internal.com

There are 2 firewalls inbetween the DMZ and the Internal network as the DMZ is hosted at a data centre.  These are Cisco ASA 5510 and 5520.  Rules have been setup which has seen us be able to telnet on port 25 between the servers.

I am not sure if the fact that the EdgeSynch works and test fine means that the DNS is setup and working fine, but I just though I would throw that one in just in case there is something special of note there.  

Would be great to get this sorted, and would appreciate any ideas.

 

by: biggles70Posted on 2009-07-26 at 21:55:06ID: 24948921

Just thought I would mention one more thing.  As we have installed the Edge Server on Windows 2008 Server with Exchange 2007 SP1 there is now no longer ADAM (Active Directory Appplication Mode).  This has been replaced by AD LDS (Active Directory Lightweight Directory Services) .

When we look at the Manager under Roles in Server Manager it says no events in the last 24 hours.  We know we have as we have created and imported new subscription files under 24 hours ago.  It does have a service listed as ADAM_Microsoft Exchange ADAM with a warning which is more than likely due to the fact that we have broken the connection for the time being until we can try again.

Anyway it might be nothing to add to my previous post, but it is info that somone might find something wrong with.  

 

by: shauncroucherPosted on 2009-07-27 at 02:03:14ID: 24949740

Yes, the ADAM service is AD LDS in 2008.

You should ensure that you can ping by FQDN from both the HUB and EDGE server.

So ping edge.dmz.com from HUB server and exchange.internal.com from EDGE server.

Also as it describes here: http://technet.microsoft.com/en-us/library/bb125154.aspx, "Port 50636/TCP is used for directory synchronization from Hub Transport servers to ADAM. This port must be open for successful EdgeSync synchronization." - so make sure this is open between the two servers and you can telnet the ports successfully (ie telnet edge.dmz.com 50636)

Shaun

 

by: biggles70Posted on 2009-08-10 at 18:16:49ID: 25065524

Hi everyone,

And thanks for the responses.  To summarise where things are at we are able to ping the Edge from the Hub and vice versa - we also added the names to the hosts file on each just in caes there was something in that.  We are able to telnet on port 25 from the Hub to the Edge and vice versa (Port 25/TCP looks fine).  The Start-EdgeSynchronization is working fine and running a Test-EdgeSynchronization also succeeds (Port 50636/TCP looks fine).  

for all intensive purposes it looks great as everything appears to be working however mail will not flow between the 2 servers.  The mail will queue up outbound on the Hub and inbound on the Edge.  

in looking for answers we are seeing a screenshot like the one shown at the link below on the Edge server:  

http://www.calipanpan.ch/EDGE%20error.jpg

This is a screenshot connected to the following post on the Microsoft Technet:

http://social.technet.microsoft.com/Forums/en-US/exchangesvrdeploy/thread/96892540-2d16-40fd-bafa-28a490081708

Unlike what is listed in that post, we are able to create and import an edge subscription, as well as successfully run a start and test sync between the both the hub and edge.

Just to reiterate we are seeing the following errors in Queue Viewer on the Hub and Edge servers.

Hub Server errors as follows:
451 4.4.0 Primary target IP address responded with: "421 4.4.1 Connection timed out."

Edge Server error is as follows:
451 5.7.3 Cannot achieve Exchange Server authentication

The Exchange 2003 server in existence prior to the transition has been removed as has the routing connectors.  the only servers in existence now are the Exchange 2007 server and the 2007 Edge server.  They are both running on Windows 2008, and if configured the Exchange server will work fine on it's own without the edge server to send and receive mail. We have also tried changing Authentication to include Integrated Windows Authentication in case this was the problem, as indicated by a couple of sources, but still without luck.

Anyway I hope this one isn't heading to the too hard basket, and if anyone has some further ideas on how to tackle it we would be greatly appreciate it.

Thanks

 

by: shauncroucherPosted on 2009-08-11 at 03:24:18ID: 25067502

First of all I would enable protocol logging for the servers involved.

http://technet.microsoft.com/en-us/library/bb124531.aspx

Especially Intraorganisational logging on the transport servers involved.

Shaun

 

by: biggles70Posted on 2009-08-24 at 21:00:48ID: 25174477

Well finally mail is flowing between the Exchange Hub and Edge Transport servers.  We did the following in the next round of troubleshooting:

Installed Microsoft Network Monitor on both the hub and edge servers and then captured packets being sent between them.  We noticed that although the edge transport was trying to establish an ESMTP session it was only receiving an SMTP.  This was seen in network monitor when comparing both ends of a particular packet transmission.  Sent on the Edge was a ehlo and received was a helo.  

From here we telneted to the Hub from the edge and ran a ehlo command to check the verbs.  These all looked fine however we then started to look at the network based on the fact that the ehlo was being received as a helo.  This in itself looked like some network device modifying the packets being sent.  The device we looked at was a Cisco 1800 series router and the setting was to do with ESMTP inspection.  This was off by defult and when enabled we telneted to the hub again and saw the verbs being blocked when running a ehlo.  The setting was then turned off (same as it was originally) and the mail started to flow.

All in all our issue was solved by enabling and then disabling an already disabled setting on the Cisco 1800 series router.  I am not exactly sure of the command as this was handled by a 3rd party, but it has to do with ESMTP packet inspection.  Turned it on and off again and it started working.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...