Exchange Sites Sync through pix

Posted on 2006-06-13
Last Modified: 2013-11-16
We are attempting to connect Exchange 2003 servers behind multiple pix firewalls and having trouble getting the mailboxes on site B to sync with Site A.

Site A - contains our main Exchange server and sits behind a pix 515

Site B - is our test lab sitting behind a pix 501 configured for a VPN tunnell to Site A.

The networks communicate for most features - file transfer, AD sync, and pretty much all other network traffic except for our Exchange problem.  Our Site A Exchange server recognizes our site B exchange server for everything except mail delivery.

Does anyone know what/where I need to add static or conduit statements on either Pix?  And if so, can you give me an example?  Or is it an Exchange configuration issue?

This issue is urgent for us, and any help is appreciated.  


Question by:fulcherjl
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 13

Expert Comment

ID: 16894832
You must have created a VPN between both sides.

This will enable you to open all the IP traffic between them.

Now, since you have two sites and exchange sits on each sites.

You need to create routing connector so that your exchange starts routing mails in between them.

LVL 10

Expert Comment

ID: 16895040
If you are in the same AD domain, then you shouldn't need a routing connector.  On both pix, be sure that the smtp fixup is turned off.  This will kill exchange config and intersite messaging.
LVL 10

Accepted Solution

Sorenson earned 500 total points
ID: 16895052
for pix 6.x

no fixup protocol smtp 25    

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.


Author Comment

ID: 16895079
Ok, I will try that - and let you know asap.

LVL 25

Expert Comment

by:Ron Malmstead
ID: 16895298
agree with Sorenson.

Please post your config, blocking out the IP's of course....that will help us to assist you  further.

Author Comment

ID: 16895353
For the moment, I have turned off smtp 25 on both firewalls -

Currently, Mails will travel from site B - out to Site A - and out to the outside world.  Email TO Site B however still gets stuck in our Test Lab Routing group connector in Site A.  I see from Sorenson, that a routing group connector does not need to be there - the connector was initially setup by a coworker as a test.  

I will remove it and see where that gets us.

keep any suggestions coming.  I welcome the assistance and will award the points as soon as mail is successfully routed to site B.

.....more soon......
LVL 10

Expert Comment

ID: 16896255
Are both exchange servers in the same AD domain?  Remove routing group connector, then stop - start SMTP under servers - protocols in ESM.

Author Comment

ID: 16896826
Yes, both Exchange servers are in the same AD domain.  We removed the routing group connector, stopped then restarted SMTP through ESM with no luck with our current test account.  Still - messages can be sent from site B to anywhere in site A/the world - but messages to mailboxes in Site B are getting hung in the Queue called testerv.BLANK.ORG

But at this point, the exchange servers are communicating on all ports - now i beleive we are up against an Exchange issue.  

Our Que list on our main Exchange Server looks like this regarding SMTP connections - Our issue is with mailboxes on "testserv"

SMTP Connector to Viruswall - [] (SMTP Connector) SMTP Default SMTP Virtual Server Active 0
SMTP Mailbox Store (MARS)   X400 Exchange MTA Active 0 SMTP Default SMTP Virtual Server Retry 4

Thanks for the Pix tip Sorenson - the points are yours.  Any other help you can offer is greatly appreciated.

General question - at this point, should i reopen this issue in another forum?

LVL 10

Expert Comment

ID: 16897350
with regards to the messages stuck in queue.  Can you telnet between the exchange servers directly on port 25 ?

ie:  telnet x.x.x.x  25  and enter simple commands (helo, etc) between the servers?  or does the viruswall intercept and proxy the requests? Exchange servers send config info via smtp, and most firewalls / smtp proxies see this traffic as non-rfc compliant and dump it.  Unfortunately it is needed :)

If the telnets both directions are clean, then I would freeze the queue, remove all messages from it, restart the queue, and then restart the smtp (under protocols, in ESM).


Author Comment

ID: 16897456
Telnet traffic seems fine between the two - getting "Hello" responses each way with no issue.

I took your suggestion about freezing the queue, removing messages, restarting the queue and restarting smtp on both servers via ESM to no avail unfortunately.

We will keep digging until we find an answer.  Thanks again for all of your help and suggestions in getting our telnet traffice between the two up and running.  if you have any other ideas, let me know.



Featured Post

How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question