SMTP traffic being disconnected after DATA is sent

Hello All,

I have an issue with one particular e-newsletter that needs to come into our network, but is being dropped for some reason.

The incoming email trajectory is:
A Cisco 2811 as our border router
Nokia IP 1220 Firewall
Sophos ES1000 Email Filter
(The transmission does not get this far. However, we have:)
SurfControl Content Filter
Exchange 2003 Front End
Exchange 2003 Back End

I have pored over our border router and Firewall logs and we can see the smtp conversations for this particular email being green-lighted and passing through.

I've also been working with the Sophos tech and he can see the following in the appliance logs.

Feb 11  TZMA01 postfix/smtpd[53381]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[53381]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54383]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54383]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[52946]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[52946]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54376]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54376]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54409]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54409]: D1E4B2220241: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54409]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54409]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54508]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[54508]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[69227]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[69227]: BB12122202C8: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[69227]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[69227]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[53226]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11  TZMA01 postfix/smtpd[53226]: disconnect from external.mail.com[203.xxx.xxx.xxx]

However, he cannot give me a reason for the disconnection.

The appliance itself is not registering the email spam (as yet) because it does not look as though the SMTP communication is finishing successfully.

By running a sniffer over the connection we can see pretty much the whole email come through, apart from the last few expected packets and the all important <.> end transmission sequence.

Our next testing step is to bypass Sophos and Surfcontrol altogether and go straight to the Exchange FE. This will only be for a very short time in order to test the extent of this particular issue (and mitigate risks).

Also, our MTU size is currently set to 1492. I will probably test setting this to 1500 and see if it works.

Has anyone seen these symptoms before?
Any assistance would be appreciated as I have exhausted all options from my end.

Thanks in advance.

Joe
joedelapazAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

debuggerauCommented:
timeouts could occur with bandwidth issues, does this occur for all outgoing mail, or only to some sites?

The time column is not reported, any chance of including this?

Also, how about establishing a test email from telnet, just to verify your connection?
0
joedelapazAuthor Commented:
we have a fairly substantial connection to the internet. somewhere within the realm of 20 mb.
and utilisation on this pipe is at a healthy level

i can confirm that the telnet connection test was successful

this is the only email that we are having issues with. all other emails are fine or at least not reporting any issues.

I've checked the logs and cannot see any other similar dropout issues that would indicate a larger problem at hand

This newsletter is sent to external and internal recipients every monday morning. At last count this newsletter is being sent to 800 external recipients and 200 internal recipients. People out on the web have not reported any issues receiving the mail. However, entry into our organisation is proving elusive.
0
joedelapazAuthor Commented:
oh, and I'm trying to get a hold of the logs with timestamps. I need to get them from the Sophos tech. So hopefully I can post them up soon.
0
Do You Have a Trusted Wireless Environment?

A Trusted Wireless Environment is a framework for building a complete Wi-Fi network that is fast, easy to manage, and secure.

joedelapazAuthor Commented:
Here is the updated log with timestamps as requested.
Thanks very much for your help thus far. Much appreciated.

Feb 11 00:06:38 TZES01 postfix/smtpd[53171]: 6C5E722202AF: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:06:38 TZES01 postfix/smtpd[53171]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:06:57 TZES01 postfix/smtpd[66386]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:06:57 TZES01 postfix/smtpd[66386]: A6CBE22202BF: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:02 TZES01 postfix/smtpd[66460]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:02 TZES01 postfix/smtpd[66460]: ED78522202D0: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:03 TZES01 postfix/smtpd[66460]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:03 TZES01 postfix/smtpd[66460]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:16 TZES01 postfix/smtpd[69234]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:17 TZES01 postfix/smtpd[69234]: 4DEBD2220207: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:18 TZES01 postfix/smtpd[69234]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:18 TZES01 postfix/smtpd[69234]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:26 TZES01 postfix/smtpd[69229]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:26 TZES01 postfix/smtpd[69229]: A9DDD222022A: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:34 TZES01 postfix/smtpd[52755]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:34 TZES01 postfix/smtpd[52755]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:56 TZES01 postfix/smtpd[53227]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:56 TZES01 postfix/smtpd[53227]: E5D5722202CD: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:57 TZES01 postfix/smtpd[53227]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:07:57 TZES01 postfix/smtpd[53227]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:08:10 TZES01 postfix/smtpd[54466]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:08:10 TZES01 postfix/smtpd[54466]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:08:28 TZES01 postfix/smtpd[53381]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:08:28 TZES01 postfix/smtpd[53381]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:08:36 TZES01 postfix/smtpd[54383]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:08:36 TZES01 postfix/smtpd[54383]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:07 TZES01 postfix/smtpd[52946]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:07 TZES01 postfix/smtpd[52946]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:26 TZES01 postfix/smtpd[54376]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:26 TZES01 postfix/smtpd[54376]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:44 TZES01 postfix/smtpd[54409]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:44 TZES01 postfix/smtpd[54409]: D1E4B2220241: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:45 TZES01 postfix/smtpd[54409]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:45 TZES01 postfix/smtpd[54409]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:56 TZES01 postfix/smtpd[54508]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:56 TZES01 postfix/smtpd[54508]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:56 TZES01 postfix/smtpd[69227]: connect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:56 TZES01 postfix/smtpd[69227]: BB12122202C8: client=external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:57 TZES01 postfix/smtpd[69227]: lost connection after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:57 TZES01 postfix/smtpd[69227]: disconnect from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:59 TZES01 postfix/smtpd[53226]: timeout after DATA from external.mail.com[203.xxx.xxx.xxx]
Feb 11 00:09:59 TZES01 postfix/smtpd[53226]: disconnect from external.mail.com[203.xxx.xxx.xxx]
0
debuggerauCommented:
By running a sniffer over the connection we can see pretty much the whole email come through, apart from the last few expected packets and the all important <.> end transmission sequence.

If the message window is getting cut off, then the TCP packets may be out of sequence or even missing, then it fails to retry and consequently resend. It may be the request to resend, but I doubt it, more likely its cut off the connection for some reason, MTU is one, I do wonder about this Nokia firewall though...

Are you able to receive the newsletter from another source and sniff it, for comparison, it would provide immensely helpful...
0
joedelapazAuthor Commented:
Hi Debuggerau,

Managed to crack it...

It was a firewall issue. A combination of "Block Crafted MIME Message MS07-026" and " Perform Aggressive MIME Strip" settings that forced the disconnection.

Thanks very much for your input with this issue. It is very much appreciated.

Cheers,
Joe
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
AntiSpam

From novice to tech pro — start learning today.