Link to home
Create AccountLog in
Exchange

Exchange

--

Questions

--

Followers

Top Experts

Avatar of mariustangen
mariustangen

Telnet command prompt goes blank when telnet port 25
Hey,

I am having a problem with both of my Exchange servers. When I try to TELNET into the servers, both internally and externally on port 25, the command prompt window goes completly blank. It does not recognize anything I write in the window and after some time I am thrown out.

When I try to telnet into port 110, the exchange server reply's immediatly with "Microsoft Exchange Server 2003 POP3 Server version 6.5.7638.1 <servername.domain> ready

What could the error be?

For the sake of the question both ports are open in my firewall (Zywall 10), the mail system works fine, and has been working fine since the last install (approx 20 months ago). But with some problems.

1. Users have reported that mail dissapear, and no feedback is given? This might be the ISP which scan's our mail for virus.
2. I have a copymachine which cannot use the internal server as smtp server. When it tries to connect the connect is fault in some way.


Hope for some answers that can fix my problem. I give this top priority since I am switchin supplier of external virus scan services tomorrow, and I need to fix this problem for both servers.


Best regards,

Marius

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Matthew MillersMatthew Millers🇦🇺

Can you telnet to 127.0.0.1 25 from the exchange server, how about ip address 25 from the exchange server?

What are the results of:
netstat -na | find /i ":25"

Since you are not getting any banner once you ping on port 25 that could mean that some other application is listening on port 25 and you will have to check the active ports list.

If thats the case then you will have to telnet the server on some other port.

Avatar of mariustangenmariustangen

ASKER

mattee76:

When i telnet on 127.0.0.1 25 I am only throwed back to the c:/. Nothing happends.

When I wrote down the netstat i get the following information back:

TCP 0.0.0.0:25   0.0.0.0:25 Listening
TCP 192.168.0.4:25 192.168.0.4:3257 Time_wait

Does this help you anything?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


greesh hem:

Could you elaborate on your answer please. How do i check for active ports, and what port should i telnet? I need port 25 to work... port 110 obviously works, but port 25 dont?

Avatar of Matthew MillersMatthew Millers🇦🇺

IUssue the following command:
netstat -nao | find /i ":25"

then open u process monitor and see what process the PID matches to.

Could you please explain a bit more in detail, what is U process monitor and PID matches?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Could you also explain a bit about what this command line does (so i can learn from it)? Thanks

Avatar of Matthew MillersMatthew Millers🇦🇺

Ok, issue the following command:
netstat -nao | find /i ":25"

Check the last number.

The issue the following command
tasklist | find /i "AbovePort#"

Substitute the "AbovePort#" with the actual port number

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Anti-Virus at the client end often causes this.  It is an attempt to stop compromised PCs spewing out junk email.  See if you can find a setting for it in your PC's AV properties.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


LeeDerbyshire:

Will this also apply if you run the TELNET command on the server (internally) and the servers has antivirus installed (Symantec Corporate edition)

mattee76:

When I issue this command, nothing happends? I can see that O is not a known syntax for the netstat, is that correct? The server running is windows 2000 server.

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

It might, if you install an Anti-Virus product that was designed for the desktop onto a server.  Or a software firewall.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


This AV software is a server rollout from a management console, I hope this is not the problem because I pay symantec a load of cash for this....

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Can you temporarily disable it, and from the server, try
  telnet localhost 25

LeeDerbyshire:

I was just thrown back to the c:\ again after i stopped the service symantec antivirus, did not seem to do the trick.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Is a firewall installed on the server, other than windows firewall?

Nope.. no firewall installert.

I persume that there is no windows firewall either since the server is running windows 2000 server?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


mattee76:
I tried to run the netstat -na | find /i ":25"
This time the information was less than last time TCP 0.0.0.0:25    0.0.0.0 LISTENING

how come the 192.168.0.4 address now is missing on the server?

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

I don't know about Server 2000, but if there was one, it would be in Control Panel/Admin Tools.

Did you have any success with netstat earlier?  Try

  netstat -a | find "smtp"

The reply is

TCP - servername:smtp - servername.domain:smtp LISTENING
TCP - servername:smtp - mx pointer:37599 CLOSING

What can i conclude form this?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

It at least confirms that the server is listening on the correct port.  Did you have any luck identifying the process name earlier?  If you type
  netstat -ao | find "smtp"
you should see a PID at the end of the line.  Start your Task Manager, and in View/Select Columns, make sure that PID is selected.  Then, match the displayed number to a process on the Processes tab.  This is just to make sure that nothing else has hijacked the SMTP port on the server.  I only have E2007 now, but on E2003, I think the process name should be inetsrv.exe .

The command o is not reconized by netstat in win2k server. I can only use the following -a, -e, -n, -s, -p proto

Okay, I had to check the whole list of processes to see if any numbers were equal, and the result is no. All processes running are running on different PID.... This problem is anoying...

Before i reinstalled the servers I was able to connect my copymachines scanner function to the smtp server. servername.domain (my server), but after the reinstallation I am unable to connect anything to this server. Mail exchange works fine, but the smtp thing does not want to work with me.

Still hoping for the solution to my problems (the situation is the same for both mail servers I have)

Avatar of Matthew MillersMatthew Millers🇦🇺

Download TCPVIEW...a GUI tool which will show end points and owning process.
http://technet.microsoft.com/en-gb/sysinternals/bb897437.aspx

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


My latest discovery is this. In my DNS I have set the "Mail Exchanger" to my ISP's smtp server, not my own with the highest priority 10.

Should I remove this "Mail Exchanger" = MX record and replace it with my own mail server, or is this correct?

As yet another fact which might be off importance. Both Exchange servers are responsible for running ROUTING AND REMOTE SERVICES which gives them an additional interface which is bogus. Could this create the problem I am experiensing?

Hoping for a solution.

Marius

mattee76:

I ran the TCPVIEW program, it reports back a bucket load of different processes. What should I be looking for? inetinfo.exe has about 31 processes running all on PID 1200

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of Matthew MillersMatthew Millers🇦🇺

You should be looking at whatever is listing on port 25...let me grab a screen shot for you.

Should i be looking for servername:25 to identify who is using port 25 - e.g for me prmmail:25 og prmmail.polarisrig.no:25 and 0.0.0.0:25

When I checked the list smtp was set to prmmail:0 and I found no processes that were running on port 25

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Yes, if you are running TCPVIEW, look in the middle column for prmmail:smtp or prmmail.polarisrig.no:smtp , and see what the process name is over on the left.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


inetinfo.exe is the process running on PID 1168 with servername prmmail:0 LISTENING

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

That seems okay.  I'm not sure if it's possible in E2003 to have the SMTP server in a stopped state while the service is running.  Worth a check, though.  If you find your Virtual SMTP Server in ESM, and right-click it, do you see the option to Start ?  While you're there, look at its properties, do you see any of the filtering options (like Connection Filtering) enabled?

The option start is not available, only stop and pause is.

None of the filtering options are enabled when I look at the IP address --> advanced --> Edit.

I have spesified both connection control and relay control under ACCESS, but I have included 127.0.0.1 togheter with my ISP IP address.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Well, it is possible to configure connection control in such a way that it's impossible to connect, and I would expect such a thing to cause the symptom that you see, i.e. an immediate disconnection.  Can you try not enabling any of the connection filtering options for the duration of a quick test?

OK... this is wierd... I have called my ISP, they can telnet my server on port 25. I cannot do the same.

Under connection control and relay I have removed all listings of IP addresses, and set both to accept all connections expect the list below... which is now empty.

Under the connector, no options for filtering is choose...

What option can be forgotten? There must be one more instanse where the IP of my ISP has been listed since this is the only IP both of my servers will accept!

Please GURU's help me fix this problem... can i remove the SMTP from windows and the reinstall the SMTP to reset all settings without removing Exchange?

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Can you tell us the public DNS name and the public IP address of the server, and I can try a telnet from here.  Just to make sure that it's not only your ISP that can contact the server.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


prmmail.polarisrig.no - 87.118.59.240

Avatar of Matthew MillersMatthew Millers🇦🇺

Apologies for dropping back into this, have been a bit busy today.
I am unable to telnet to 25 on that address, but if i run a capture i am actually seeing traffic back and forth.

Can you confirm you have removed the connection restrictions? have you stopped restarted SMTP?
net stop smtpsvc && net start smtpsvc

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

No, it does not work from here.  There is no banner, and it disconnects as soon as you type anything.

Can you enable logging on the SMTP Virtual Server, and see if any attempted connections get logged?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


mattee76:

As a wrote above. connection control and relay restriction is now empty and both are set to "accept all addresses exept those below".

Under ipaddress (set to the servers internal address, not unassigned) advanced - edit - no filters are chosen.

I have now completed the command line you requested, smtp has been reset.

Still connection to local host lost

I almost believe the next step is to reinstall my exchange servers.... can this be true????? OMG... I have been at the phone with 2 relativly competent exchange guys and noeone can identify what has gone wrong with both of my servers.

I am preparing a backup of one of the servers now before I commence a reinstallation of exchange, perhaps even a demotion of win2k server to reinstall IIS on the server.....

Please give me some advice quickly so I can find a better alternative....???

Avatar of Matthew MillersMatthew Millers🇦🇺

Why dont you disable your existing virtual server, change the port to something else.
Create a new SMTP VS on TCP/25...see how that goes.
You have disabled any local antivirus software?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

You will need to find out if the telnet requests are even reaching the server.  It may actually be your firewall that is responding, and not the server.  Turn on logging on your SMTP Virtual Server, and see if anything gets logged when you attempt a connection.

If you don't see anything logged, you will need to get a protocol analyzer, and make sure that the attempted connections are really reaching the server:
http://www.ethereal.com/

LeeDerbyshire:

I talked to my ISP, they said that they got in contact with my mail server, and recieved some report starting with 220... isn't that good enoug? I hope my firewall does not respond with such a message?

Avatar of LeeDerbyshireLeeDerbyshire🇬🇧

Yes, anything beginning with a 2 is good.  Some firewalls, such as PIX, are known to do a lot of protocol screening.  I don't have one, but it seems that a PIX will handle a lot of the communication before it even gets to the server.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


mattee76:

When I create a new SMTP VS i get a white circle on the icon. I am not able to start, stop or pause the new VS even though i have changed the TCP port on the Default and stopped it.

I changed the TCP port under IP Addresses - Advanced - 192.168.0.4 - Edit - TCP port 25 (now set to 30)

How can i get the new SMTP VS to start?

My firewall is a basic thing.. nothing fancy or flashy.. since the feedback also included my servername they gave me the thumbs up. Since mail is working fine both internally and externally they are obviously getting thru... But I need to let others thru so as long as my servers are only "bound" to one IP I have a problem.

Any tips on how I can get the new SMTP VS to start? so far all options (start, pause and stp) are grey, and there is a white circle where the red cross is if the SMTP VS is stopped.

Avatar of Matthew MillersMatthew Millers🇦🇺

I think we can possibly ignore the edge firewall as you are saying that you cannot get a connection to server internally either.

I should have meantioned this, while doing any of this, connectivity for any smtp traffic will not work as expected.

So you have stopped both VS?
Can you issue the command "net stop smtpsvc"
Then issue the command
netstat -na | find /i ":25"
Is anything still listening on 25?

net start SMTPSVC

Are you able to start the "new" VS now?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


When I issued netstat -na | find /i ":25" it just jumpes to c:\> nothing is reported back, is this because nothing is running or should I get some type of feedback?

I have preformed the net stop command prior to the netstat command

Avatar of Matthew MillersMatthew Millers🇦🇺

That should be fine.
Can you start the service again, then try and start the new VS?
Rerun the netstat command, do you see anything listening on 25 now?

C:\>netstat -na | find /i ":25"
  TCP    0.0.0.0:25             0.0.0.0:0              LISTENING

The old VS is stopped with a red cross over the icon. The new VS will not start, the options are all grey. I have set them to different TCP values. Any clue how I can start the new SMTP VS?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Is it time to try more drastical measures?

Avatar of Matthew MillersMatthew Millers🇦🇺

Set both VS to use the same IP, but the old VS configure with a different port.
Set the new one to use 25
What happens now?

Still not able to start the new SMTP VS, there seems to be something wrong with the SMTP VS on both servers. What would you recommend me to do next?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Matthew MillersMatthew Millers🇦🇺

When you restart the actual SMTPSVC...do you get any events in the eventlog, can you post these?

In the System log i get an error for the Schannel Source:
Event ID: 36871 Source: Schannel Description: A fatal error occurred while creating an SSL server credential (This error happends twice every time i restart the SMTP it seems)

In the application log it says no errors only information:
Event ID 332 and 334.
332 - SMTP service has been started, initializing queues
334 - SMTP service instanse 1 has been started

Avatar of Matthew MillersMatthew Millers🇦🇺

Do you know if you are accepting secured SSL connections?
Can you check your original SMTP VS...

Access tab
Is the "communication" button grayed out?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Communication is grayed out yes. I am not accepting SSL as i know of. When i connect with my activesync i always drop clicking off for SSL connection.

Mattee76 as you are a GURU one the subject, what do you think my next move should be? Is it time to try to reinstall Exchange and IIS to see if that corrects the problem?

Avatar of Matthew MillersMatthew Millers🇦🇺

Sorry, i went home! And I am heading out now...I will try and attend to this over the weekend.
If it were me, I would try and fix the issue rather than rebuild...I hate it when people do that!!

You know there are many many resources which you can use on the internet to assist in your endevours to fix this problem...but I will be back.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


I will wait... To tired to start rebuilding now. Hope for some more constructive tips over the weekend. Thx so far

Avatar of Matthew MillersMatthew Millers🇦🇺

Hi,

We can continue to try and resolve the issue. Or you can go ahead and try and do a reinstall.

Reinstalling can be done in place and will not affect your current databases, it will however, replace any missing configuration settings.

Make sure you know what current service pack/updates are installed for exchange.
Remove second SMTP VS
setup /reinstall
Run through the wizard to reinstall
Apply service packs + updates

Thanks
Matthew

What about removing the smtp service without reinstalling Exchange?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


ASKER CERTIFIED SOLUTION
Avatar of Matthew MillersMatthew Millers🇦🇺

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

I have read an article on Technet (microsoft) that said I had to disconnect all the mailboxes before I remove the Exchange server. Will the prior steps be different if I only reinstall Exhcange?

Furthermore I have updated Exchange with Version 6.5, Build 7638.2 Service Pack 2, are there other updates I need to take into account before I reinstall (I checked the following properties to find the version: ESM -- > AG --> FAG --> Servers --> Server properties --> General; is that correct)?

Avatar of Matthew MillersMatthew Millers🇦🇺

Please note that you are NOT removing the exchange server, you are doing an in place reinstall.
In your case it is:

Run a backup of your exchange server (for safety sake)
Remove IIS (incl SMTP)
Delete metabase.bin
Reinstall IIS (incl SMTP) (WWW/SMTP/NNTP)
Reinstall exchange server
Reinstall exchange service pack 2



Thank you. This project will be postpone till next week. How many hours do you think I willl have to expect for such a operation?

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Matthew MillersMatthew Millers🇦🇺

Not long...60mins.

I am about to start the installation. But I want to ensure one last curiousity. The server is in a Domain, performing the above mentioned list will not interfere with AD or any other instances on the server?

Avatar of Matthew MillersMatthew Millers🇦🇺

Are you saying that exchange is installed on a DC?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


The server has been promoted with DCPROMO, but is not the primary domain controller. The other server is the DC running DNS and DHCP. This server is a secondary domain controller.

Thanks, this opened up the SMTP telnet for both the localhost and the new ISP! However... now the IMAP4 and POP3 services will not start. The error given is 1610 - The configuration data for this product is corrupt. Will search for a solution.

Best regards,

Marius

btw, I could not find METABASE.bin after IIS was removed? I checked the INETSRV folder under SYSTEM32... this acceptance was to early... everything is down now.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.

Exchange

Exchange

--

Questions

--

Followers

Top Experts

Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.