Solved

exchange 2010 not recieveing mail, TMG 2010 - Exchange edge trans - internal exchange server

Posted on 2010-08-26
21
2,456 Views
Last Modified: 2012-05-10
Hi all,


having problems recieveing external emails, i can send fine btu not recieve

i just changed the external address of my firewall thats all ive done
i have been on canyouseeme.org port 25 - success

we have tmg2010 and exchange edge transport installed on the same box and then thats relayed to our internal exchange server

ive been looking around everywhere as to why i wouldnt be able to recieve cant see nothing

i can verify the port is fowarded correctly and our mx record is pointing to the right place

can anyone help me out on where to start looking?

Thanks
0
Comment
Question by:awilderbeast
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 15
  • 6
21 Comments
 
LVL 3

Expert Comment

by:Big_Steef
ID: 33530571
start by connecting via telnet from outside your netork on port 25:

telnet 82.x.x.x 25

and see if it replies. It may be that you need to put in a recieve connectory.

if you get connection, type the following:

helo me <enter>
mail from:email@domain.com <enter>
rcpt to:youremail@yourdomain.com <enter>
data <enter>
Subject:This is a test <enter>
Testing <enter>
. <enter>

and see what errors you get...

0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33530724
ok i used my phone to get on externally, the crappy app didnt work though

it did manage to connect though and it said the service was ready

i did however get this reply testign from hotmail

The following message to <alex@domain.org> was undeliverable.
The reason for the problem:
5.1.0 - Unknown address error 550-'5.7.1 External client with IP address 212.50.160.34 does not have permissions to submit to this server. Visit http://support.microsoft.com/kb/928123 for more information.'

thats not my ip address in there, i think its one of my isps
0
 
LVL 3

Expert Comment

by:Big_Steef
ID: 33530747
You need to set up a new receive connector.

I have stepped out for 10 minutes, I will give you a powershell script as soon as I get to my desk.
0
MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

 
LVL 1

Author Comment

by:awilderbeast
ID: 33530790
ive used mxtoolbox.com

i have created a new recive connector on the edge trasnport/firewall server still failing


220 mail.domain.org Microsoft ESMTP MAIL Service ready at Thu, 26 Aug 2010 13:36:58 +0100


 Not an open relay.
 0 seconds - Good on Connection time
 5.912 seconds - Warning on Transaction time
 OK - 7xx.xxx.xxx.xx3 resolves to static-7xx-xxx-xxx-xx3.karoo.kcom.com
 Warning - Reverse DNS does not match SMTP Banner

Session Transcript:
HELO please-read-policy.mxtoolbox.com
250 mail.constructionworks.org Hello [64.20.227.133] [140 ms]
MAIL FROM: <supertool@mxtoolbox.com>
250 2.1.0 Sender OK [156 ms]
RCPT TO: <test@example.com>
550 5.7.1 Unable to relay [5195 ms]
QUIT
221 2.0.0 Service closing transmission channel [140 ms]

Open in new window

0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33531061
i just ran your test code above internally

sent it from me > to me

filled it all in then got access denied at the end
does that help?
0
 
LVL 3

Expert Comment

by:Big_Steef
ID: 33531268
from the outside, it appears to be taking the mail.

250 2.6.0 <181ce4f8-701f-48f6-b730-3e053337e159@CH-FW.works.local> [InternalId=1
50] Queued mail for delivery

can you tell me if you got that mail?
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33531304
all i have done is changed the external ip address of TMG from 192.168.200.1 to 192.168.201.1 ive changed my routers port foward the firewalls NIC and thats it, ive searched though my firewall rules and none of them reference 192.168.200.1 at all
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33531357
i havent got any :S

i checked my firewall logging, it is allowing it thought but isnt going anywhere

how can i check where there getting stuck/rejected?
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33531373
.6.0 <181ce4f8-701f-48f6-b730-3e053337e159@CH-FW.works.local> [InternalId=1

i noticed its responded with our internal namespace, should it be doing that?

shouldnt it be responding with external name space? mail.constructionworks.org?
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33531522
ok ive took screens of both my external recieve connectors

the first one is from the firewall (edge transport server)

the second is from the internal exchange server
Firewall-recieve-connector.jpg
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33531530
Exchange receive connector
exchange-rec-connector.jpg
0
 
LVL 3

Expert Comment

by:Big_Steef
ID: 33532180
can you show a get-queues on the edge server and see if they are still sitting in the queue on that box? there are mails somewhere and i fifnt get a bounce...

i would suggest that your recieve connector on your edge box is correct but the send connector on the edge box isnt working.

are they on the same network and is there a cisco anywhere inbetween?
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33532253
get-queues fails?

i get a bounce back from hotmail everytime

the exchange server is on  192.168.101.2 and the edge/firewall 192.168.101.10 (internal) 192.168.201.1 (external)

then external 192.168.201.1 goes to a cisco 877 192.168.201.254 and i have a nat rule that forwards port 25 and 443 to 192.168.201.1 on that

[PS] C:\Windows\system32>get-queues
The term 'get-queues' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the
spelling of the name, or if a path was included, verify that the path is correct and try again.
At line:1 char:11
+ get-queues <<<<
    + CategoryInfo          : ObjectNotFound: (get-queues:String) [], CommandNotFoundException
    + FullyQualifiedErrorId : CommandNotFoundException

[PS] C:\Windows\system32>

Open in new window

0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33532318
my bad didnt need an s

no emails here :S
[PS] C:\Windows\system32>get-queue

Identity                                    DeliveryType Status MessageCount NextHopDomain
--------                                    ------------ ------ ------------ -------------
CH-FW\6                                     SmartHost... Ready  0            smtp.karoo.co.uk
CH-FW\Submission                            Undefined    Ready  0            Submission

Open in new window

0
 
LVL 3

Expert Comment

by:Big_Steef
ID: 33532326
sorry, its get-queue

should return somehting like this:

[PS] C:\Windows\system32>Get-Queue

Identity                                    DeliveryType Status MessageCount NextHopDomain
--------                                    ------------ ------ ------------ -------------
server\Submission                              Undefined    Ready  0            Submission
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33532372
yeah see above ^^
0
 
LVL 3

Accepted Solution

by:
Big_Steef earned 500 total points
ID: 33532501
ok..

i have done another test and you are getting the following:
#5.0.0 smtp; 5.1.0 - Unknown address error 550-'5.7.1 External client with IP address xxx.xxx.xxx.xxx does not have permissions to submit to this server. Visit http://support.microsoft.com/kb/928123 for more information.' (delivery attempts: 0)> #SMTP#


This issue occurs if the IP Block list is enabled on the Edge server in the receiving Exchange 2007 organization.

can you check the ip block lists (anti spam) in the hub server and edge server
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33532592
bah why would exchange block my isps smtp server (thats where we get all our mail from) ive added to allow list and removed it from block


[PS] C:\Windows\system32>get-queue

Identity                                    DeliveryType Status MessageCount NextHopDomain
--------                                    ------------ ------ ------------ -------------
CH-FW\6                                     SmartHost... Ready  0            smtp.karoo.co.uk
CH-FW\Submission                            Undefined    Ready  3            Submission

but the mail still isnt in my inbox yet
how can i move it on now?
ive probably broke something along the way knowng my luck!
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33532619
infact heres a list of blocked ips that i havent done myself at anypoint

do you know who any of the below belong to, so i can add them to my sages

are the 65. ones Microsoft's?
blocked.PNG
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33532720
i queried them and they are MS ones mostly ive added them to safes now

so i have 13 emails in my queue now and dont know how to get them moved on

can you help?
0
 
LVL 1

Author Comment

by:awilderbeast
ID: 33533165
it says the emails are stuck in a local loop


Identity: CH-FW\Submission\573
Status: Retry
Size (KB): 4
Message Source Name: SMTP:External
Source IP: 212.50.160.34
SCL: 0
Date Received: 26/08/2010 16:46:50
Expiration Time: 28/08/2010 16:46:50
Last Error: A local loop was detected.
Queue ID: CH-FW\Submission

Open in new window

0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question