Disable ICMP ping on PIX will disable SMTP Virtual Connector ??

Posted on 2006-06-06
Last Modified: 2013-11-15
Due to security reason, I have disabled the ICMP ping on my PIX. Afterwards, I find that the Exchange server couldn't route my domain users's e-mail to other Exchange server (hosted in other country). I then review the queue in the Exchange and find that the connector to the other Exchange server is not available. According to my memory, it normally use this queue to route my internal e-mail. However, when I enable the icmp ping on PIX, everything work fine after few minutes.

Two sites are connected through VPN through PIX. In fact, only ICMP is blocked. Other than that, two Exchange could be pinged each other and POP3, SMTP is working fine through the PIX.

Why does this happen ?
Question by:AXISHK
    LVL 4

    Expert Comment

    A simple answer would be to just enable ping on that vpn.  Disable ping for all other locations, but allow it for the vpn.

    LVL 23

    Accepted Solution

    Just disable the ICMP check in Exchange.

    See here for a better explanation:

    Reachability   DSAccess uses Internet Control Message Protocol (ICMP) to ping each server to verify that the server is available. DSAccess also verifies that the directory server is reachable over port 389 (for domain controllers) and port 3268 (for global catalog servers).

    If you use ICMP to determine if a server is available, you might create a problem if all connections in your network do not support ICMP. For example, an Exchange server might reside in a perimeter network, which has no ICMP connectivity between the Exchange server and the domain controllers. In this situation, you should disable the ICMP check and set the following registry parameter to zero.

     HKEY_LOCAL_MACHINE\SYSTEM \CurrentControlSet\Services\MSExchangeDSAccess
    Value Data
     DSAccess uses the ping protocol if there is no registry key does or it is not set to 0,

    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Join & Write a Comment

    Create your own, high-performance VM backup appliance by installing NAKIVO Backup & Replication directly onto a Synology NAS!
    Workplace bullying has increased with the use of email and social media. Retain evidence of this with email archiving to protect your employees.
    This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
    This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    23 Experts available now in Live!

    Get 1:1 Help Now