Exchange and Pix 501 , some outgoing email not getting through

I recently setup a pix 501, and for some reason I cannot send to Verizon.net Comcast or yahoo mail, along with some other email address's . Mail was working fine before the PIx install, Most email is going out fine just some aren't>??
  I checked The Exchange mail Queue , nothing there, nothing on the spam filter??
  Any help would sure be appreciated.
   Even when i reply to a mail coming in .It still wont go out.
   Am I correct in thinking the PIX is fine, since it is either allowing or not as per the access list?
   At wits end
 
mphil2007Asked:
Who is Participating?

[Webinar] Streamline your web hosting managementRegister Today

x
 
kieran_bConnect With a Mentor Commented:
I do object in part, I mean the asker did solve it by themselves, but being identified as being on a blacklist (and how to remove himself) is something that would have to be followed regardless.  Of course, they are only points, and if the asker honestly feels none of our comments were of value, then I do not object.
0
 
Matthew MillersCommented:
You may need to disable SMTP fixup (on the cisco)

Or the destination domains may require that you have a reverse lookup configured (your ISP)
0
 
kieran_bCommented:
Drop your domain in here and tell us what it throws up -> http://www.dnsreport.com

I agree with Matt, odds are it is SMTP fixup
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
mphil2007Author Commented:
Mattee76,
 Thank you for your prompt reply

I added the no fixup smtp 25 line earlier today before i left work and tested, stil nothing
Would I need to do anything to the reverse lookup if all I did was add the pix 501?, everything was working fine prior to that
 
this is the exact notification I received from Comcast , on a reply about a work order..

 "there was a smtp communication problem with recipients email server"
 So its getting past the pix i guess?
 Could for some reason all these companies suddenly have me as spamming for some reason?

 I am completely confused why some outgoing mail is fine and some aren't
 static ip etc are all the same? nothing has changed except the addition of the pix
  I checked the queue , no spam there, i know Exchange server is not relaying,

Any help would be appreciated of course
 
0
 
kieran_bCommented:
>>So its getting past the pix i guess?

We don't think that the PIX is in the way, we think it is interfering
0
 
Matthew MillersCommented:
Are you actually getting that error from comcast or is your exchange server returning that error? I would have thought it to be your exchange server.

Can you telnet to any of the comcast.com MX on port 25 from the mail server?

C:\>nslookup -type=mx comcast.com
Address:  192.168.230.1

Non-authoritative answer:
comcast.com     MX preference = 20, mail exchanger = mx1.comcast.com
comcast.com     MX preference = 20, mail exchanger = mx2.comcast.com
comcast.com     MX preference = 5, mail exchanger = mx3.comcast.com

mx2.comcast.com internet address = 208.17.35.40
mx3.comcast.com internet address = 24.40.8.248
mx1.comcast.com internet address = 24.40.8.248
0
 
mphil2007Author Commented:
Thanks for the reply kieran_b:

I checked DNS stuff , and .. it says In fact     FAIL      Open DNS servers  .. which is odd because 2 months ago I took over the exchange server, used dnsstuff ,, checked and fixed eveything, wow why would suddenly revert to opn dns server again, going to remote in and check dns server again
 I didnt even think to look since it was fixed not long ago,, when i took it over it was getting bombarded ,, as an open relay .. hmmm

in my config on the pix it says  no fixup protocol smtp 25 now, i just added a "no" before the command, im pretty sure that was right but, just thought i would check
 well , remoting in to try and figure out why my dns is failing hmm
0
 
kieran_bCommented:
Open DNS servers is not that much of a problem - it is not open relay

No other errors?
0
 
mphil2007Author Commented:
nope , a couple of warnings (yellow) , the dns server was the only error in red,
 should i post the config from pix? im really at a loss here.
 I am currently VPN'd in , at least i got the pix up and vpn running, now this.....
  people are freaking at my job, .. I gotta figure something out.. if anything i need to post let me know i am on the server now.
 Really appreciate the help!!!
0
 
kieran_bCommented:
Post your domain name, and we will check it out
0
 
mphil2007Author Commented:
mattee
i typed nslookup
>mx comcast.com

server comcast.net
address 68.87.60.144

dns request timed out
0
 
mphil2007Author Commented:
matte
my bad,
i typed the nslookup wrong., it came back the same as yours
sorry my bad
0
 
mphil2007Author Commented:
aosdigital.com
liitle hesitant about typing that here, guess its safe ?
 :)
0
 
kieran_bCommented:
You have a bad SMTP Greeting, you need to change it to mail.youdomain.com -> http://www.block.net.au/help/SMTP-Greeting

That would explain it...
0
 
mphil2007Author Commented:
under fully qualified domain name,
it is already aosdigital.com , i see from the link posted above it should say

 servername.aosdigital.com   ??

ok i have changed it to that, let me recheck DNS stuff.com
0
 
kieran_bCommented:
Yes, it should be mail.aosdigital.com
0
 
mphil2007Author Commented:
Kieran,
 Do you know how long it would take for that to update?
   I am testing by sending mail from my office to an email at verizon that i am checking from home, and still not going though.
   
0
 
kieran_bCommented:
It has updated now.

But I have more bad news - you are listed on a stack of blacklists;

Run through this -> http://www.amset.info/exchange/spam-cleanup.asp

The, run through each of these and request removal -> http://www.mxtoolbox.com/blacklists.aspx

That is going to take a few days, until then you can route all outbound mail via your ISPs mailserver -> http://www.amset.info/exchange/smtp-connector.asp

Kieran
0
 
mphil2007Author Commented:
thanks for the links Kieran,
Looking like i have my work cut out for me,
guess i need to find out if i am still being blacklisted before correcting the problem
  So weird this happened same time i put that pix in.. hmmm co-incidence.
   Well, back in a  bit gonna get busy
  Thank you for your help
 
   
0
 
mphil2007Author Commented:
Hi Guys,
 Well, it turns out there was a bot on the network, someone disbaled their anti-virus ,
   removed anti-virus etc , cleaned all the machines , installed a server roll-out anti-virus,
   added a line to pix conifg only allowing smtp from the mail server out, denied the rest, unblocked all the blacklists , most of mail is back up.
  Thanks for your help , much appreciated.. thanks for the links, they came in handy for sure!
        mike
0
 
mphil2007Author Commented:
i submitted the points again and added a post ., it is not showing uo?
0
 
Vee_ModCommented:
This question is closed out and we can all move on to other questions.
Thank you to all who participated.

VM
0
All Courses

From novice to tech pro — start learning today.