Exchange 2003 connection problem

I have a Exchange 2003 box, relatively new.  That last few days it is randomly not sending or receieving.  A re-boot fixes the problem.  Where should I begin?
Rob TimmermansIT SpecialistAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

redseatechnologiesCommented:
Is there anything in the queues?
0
Rob TimmermansIT SpecialistAuthor Commented:
They were backing up.  Seem to be going out now after the re-boot.
0
redseatechnologiesCommented:
Right, what were they backing up with?

(you might have to wait to see it build up again)

When it does, click on one of the queues and it will show a message at the bottom

-red
0
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

Rob TimmermansIT SpecialistAuthor Commented:
After the reboot the queues have dropped back to normal.  
0
Rob TimmermansIT SpecialistAuthor Commented:
on the yahoo.com it said connection dropped by host, then it re-connected and says no additional informatio n availble right now
0
redseatechnologiesCommented:
Until we see what they were stopped for, it will only be guessing.

With that in mind, my guess would be anti-virus/anti-spam software.  Infact, I will go a step further, do you have symantec mail security on that server?
0
redseatechnologiesCommented:
connection dropped by remote host could be a spam setting - could be your AV

run your domain through http://www.dnsreport.com and make sure there are no issues listed there - then wait for it to back up
0
Rob TimmermansIT SpecialistAuthor Commented:
No.  There is currently no anti-virus software on this server or anti-spyware.
0
Rob TimmermansIT SpecialistAuthor Commented:
dnsreport looks good.
0
Rob TimmermansIT SpecialistAuthor Commented:
Firewall?  Though, re-booting clears the issue.
0
redseatechnologiesCommented:
could be the firewall, there are known issues with cisco firewalls (among others) and this kind of stuff

and rebooting could still fix that (by trying again)
0
Rob TimmermansIT SpecialistAuthor Commented:
It is a Watchguard.  The firewall config died on us last week.  I had to re-build last Thursday.
0
redseatechnologiesCommented:
that sounds promising - still, an error would help

I am researching now though

-red
0
redseatechnologiesCommented:
can you disable the smtp proxy server in the server?
0
redseatechnologiesCommented:
server=firewall
0
redseatechnologiesCommented:
0
Rob TimmermansIT SpecialistAuthor Commented:
I will take a look and let you know.
0
Rob TimmermansIT SpecialistAuthor Commented:
I haven't checked everything with your posted link yet, I tried something to the incoming smtp proxy on the firewall at the request of Watchguard, after the config saved I lost all inbound Email. Hmmm.
0
Rob TimmermansIT SpecialistAuthor Commented:
If this helps.  When there is a connection problem coming in,if I stop and start the smtp virtual server it clears up for a while.
0
redseatechnologiesCommented:
I was referring to the actual post that I link directly too

I would still love to know what the queues say now
0
Rob TimmermansIT SpecialistAuthor Commented:
I found something in the event viewer under applications.  2 entries when the problem occurs.  First is a warning about a UDP connection to the DC, the second right after is that exchange is unable to locate a DNS.  Now when I pinged the DNS name it came back with the wrong IP (it cam eback with the IP i use on the DNS for a VPN) so I turned of that network connection on the DNS that is not needed, re-booted and then it resolved the correct IP for the DNS name.  Thoughts?
0
Rob TimmermansIT SpecialistAuthor Commented:
It takes roughly an hour after restarting services, but the exchange server reports unable to see dns server.  Help!
0
Rob TimmermansIT SpecialistAuthor Commented:
Allright.  I just started to delete 1000 messages in a queue for msa.hinet.net and mail started comgn backin without re-starting services.
0
redseatechnologiesCommented:
is msa.hinet.net legitimate?

As for the DNS problem you have there, that is a bit of a concern.  Paste an ipconfig /all here of the exchange server and the primary DC (which I assume is the primary DNS)

-red
0
Rob TimmermansIT SpecialistAuthor Commented:
msa.hinet.net according dnsreport.com is.
 
DC:
Windows IP Configuration

   Host Name . . . . . . . . . . . . : bvrc01
   Primary Dns Suffix  . . . . . . . : bluevalleyrec.local
   Node Type . . . . . . . . . . . . : Unknown
   IP Routing Enabled. . . . . . . . : Yes
   WINS Proxy Enabled. . . . . . . . : Yes
   DNS Suffix Search List. . . . . . : bluevalleyrec.local

Ethernet adapter bluevalleyrec.local:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 PT Dual Port Server Ada
pter
   Physical Address. . . . . . . . . : 00-15-17-02-BC-05
   DHCP Enabled. . . . . . . . . . . : No
   IP Address. . . . . . . . . . . . : 192.168.0.15
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.0.3
   DNS Servers . . . . . . . . . . . : 127.0.0.1
Exchange:
Windows IP Configuration

   Host Name . . . . . . . . . . . . : exchange01
   Primary Dns Suffix  . . . . . . . : bluevalleyrec.local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : bluevalleyrec.local

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 XT Network Connection
   Physical Address. . . . . . . . . : 00-06-5B-F2-5F-51
   DHCP Enabled. . . . . . . . . . . : No
   IP Address. . . . . . . . . . . . : 192.168.0.17
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.0.3
   DNS Servers . . . . . . . . . . . : 192.168.0.15                
   Primary WINS Server . . . . . . . : 192.168.0.15
0
redseatechnologiesCommented:
ok, that look alright.

So what are you pinging that is giving you the incorrect name/ip address?
0
Rob TimmermansIT SpecialistAuthor Commented:
When pinged the name of the dns it came back with a valid IP for the dns server but the ip it cam back with is used for a vpn not the dns ip.  I turned off the vpn nic on the dns and that resolved that problem for now.  What is happening now is I am getting (roughly every hour) a SMTP dns connection error, 1 is stating UDP connection the other smtp error just says exchange is unable to locate any dns.
0
redseatechnologiesCommented:
Run the exchange best practices analyzer - sounds like you have some serious DNS issues here;

http://www.exbpa.com

-red
0
Rob TimmermansIT SpecialistAuthor Commented:
Which check option do you want to see results for? Health, connectivity, etc?
0
redseatechnologiesCommented:
do a health check
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Rob TimmermansIT SpecialistAuthor Commented:
I am letting the 2 hour health go now, I will post an update when it is finished, though Ku is playing in a few hours, so it may be late tonight.
0
redseatechnologiesCommented:
You can run that overnight - if you want some quick results now, I should have pointed you at the connectivity test
0
Rob TimmermansIT SpecialistAuthor Commented:
Health(2 Hour):
Intelligent Message Filter recommendation :  
 The Intelligent Message Filter was not detected and at least one computer in the organization is running Exchange Server 2003. The Intelligent Message Filter can help reduce unsolicited commercial electronic messages.
  Tell me more about this setting.  
 
Organization: BVRC  
 
  Global outgoing message size not set Organization: BVRC
 The maximum outgoing message size is not set. This can cause reliability problems.
  Tell me more about this issue and how to resolve it.  
 
  Global incoming message size too high Organization: BVRC
 The maximum incoming message size is set too high. This can cause reliability problems. Maximum message size is 40 MB.
  Tell me more about this issue and how to resolve it.  
 
Admin Group: First Administrative Group  
 
Server: EXCHANGE01  
 
  3GB is not set Server: EXCHANGE01
 Exchange mailbox server exchange01.bluevalleyrec.local has 1 GB or more of memory, accommodates 64 mailboxes, and does not have /3GB set in the Boot.ini file. Greater scalability would be achieved if this were set. Memory detected: 2559 MB.
  Tell me more about this issue and how to resolve it.  
 
  Volume shadow copy service update available Server: EXCHANGE01
 An important update for the volume shadow copy service is available on server exchange01.bluevalleyrec.local. This resolves issues such as kernel resource depletion. See Microsoft Knowledge Base article 891957 for further information.
  Tell me more about this issue and how to resolve it.  
 
  Domain controller server response time Server: EXCHANGE01
 Round-trip times from Exchange server EXCHANGE01 to Active Directory server bvrc02.bluevalleyrec.local are taking 44 ms. This may cause Exchange performance problems.
  Tell me more about this issue and how to resolve it.  
 
  Open relay test failed Server: EXCHANGE01
 SMTP instance 'Default SMTP Virtual Server' on server EXCHANGE01 failed the open relay test. Restrictions are in place, but the workstation or user running this tool is capable of using the open relay. Verb return: Respond = 250 2.1.5 ExBPA-OpenRelayTest@Fabrikam.com ,.
  Tell me more about this issue and how to resolve it.  
 
  SMTP message failure warning Server: EXCHANGE01
 Bad mail messages (non-delivery of delivery status notification) exceeds an average of 1000 per day for SMTP instance 'Default SMTP Virtual Server' on server EXCHANGE01. There may be a mail flow problem. Bad mail message average per day: 38197.
  Tell me more about this issue and how to resolve it.  
 
  SMTP performance warning Server: EXCHANGE01
 The SMTP queue folder for instance 'Default SMTP Virtual Server' on server EXCHANGE01 is located on the same drive as the system partition. This may cause performance problems. Current queue path: C:\Program Files\Exchsrvr\Mailroot\vsi 1\Queue.
  Tell me more about this issue and how to resolve it.  
 
  'MSGINA.DLL' driver update available Server: EXCHANGE01
 The version of 'MSGINA.DLL' installed on server exchange01.bluevalleyrec.local can cause working sets to be improperly trimmed when Terminal Services is used. This can cause reduced performance and excessive page file activity. Refer to Microsoft Knowledge Base article 905865 for more details. Installed version of 'MSGINA.DLL': 5.2.3790.1830 (srv03_sp1_rtm.050324-1447).
  Tell me more about this issue and how to resolve it.  
 
  Application log size Server: EXCHANGE01
 As a best practice, the size of the 'Application' log on server exchange01.bluevalleyrec.local should be increased. The current size is 16MB. For servers running Microsoft Exchange, a size of 40MB or more is recommended.
  Tell me more about this setting.  
 
  Single global catalog in topology Server: EXCHANGE01
 There is only one global catalog server in the Directory Service Access (DSAccess) topology on server EXCHANGE01. This configuration should be avoided for fault-tolerance reasons.
  Tell me more about this setting.  
 
  SMTP server accepts basic authentication Server: EXCHANGE01
 SMTP instance 'Default SMTP Virtual Server' on server EXCHANGE01 is configured to allow basic authentication. For additional security, this can be disabled on back-end mailbox servers.
  Tell me more about this setting.  
 
  Consider implementing storage quotas Server: EXCHANGE01
 Storage quotas are not implemented for mailbox store 'Mailbox Store (EXCHANGE01)' on server EXCHANGE01. Implementing quotas can improve database management and operations.
  Tell me more about this setting.  
 
  BIOS update available Server: EXCHANGE01
 The basic input/output system (BIOS) on server exchange01.bluevalleyrec.local (model PowerEdge 2600) is out of date (latest is A14). Current BIOS level: A04.
  Tell me more about this setting.  
 
  Crash upload logging disabled Server: EXCHANGE01
 Exchange fatal error information on server exchange01.bluevalleyrec.local is not automatically sent to Microsoft for analysis. It is recommended that you enable this feature through the Exchange System Manager.
  Tell me more about this setting.  
 
  Outlook connection range Server: EXCHANGE01
 All versions of Outlook are allowed to access server exchange01.bluevalleyrec.local. It is recommended that older versions be blocked.
  Tell me more about this setting.  
 
  WINS secondary is blank Server: EXCHANGE01
 The secondary WINS server address for network interface '[00000001] Intel(R) PRO/1000 XT Network Connection' on server exchange01.bluevalleyrec.local is blank. If primary WINS resolution fails this server may be unable to resolve names.
  Tell me more about this setting.  
0
redseatechnologiesCommented:
Review each of those items, and make the changes recommended.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.