[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1059
  • Last Modified:

TLS emails between 2 organizations can't route properly

Hi,

I have a SBS server 2003, has run smoothly all the time.  Recently, the client request establish secured (TLS) communication with One external party.

The external part setup their TLS settings, with Certificate Verification Required, and 128bit Encryption Level.

On our server
originally has:
1 network: 192.168.40.100
1 Default SMTP virtual server;
1 Small Business SMTP Connector

My new configuration:
Point the existing Default SMTP virtual server associated to 192.168.40.100 address;
Added 2nd IP address to the network card: 192.168.40.99
Created 2nd secured SMTP virtual server, and associated it to 99 address;
purchased and installed Certificate from GoDaddy on secured SMTP virtual server, with FQDN: abc.com.au, (should it be mail.abc.com.au?)
Ticked Require TLS on Access-Authentication (with Anoymous, and Intergrated ticked as well);
Access - Communication: Require Secure Channel, and Require 128 ticked;
Delivery - Outbound Security: require TLS ticked;

Created 2nd connector
General page, I selected use DNS to route to address space..., intended to send email straight out to the destination;
General - Local Bridgehead: pointed to the secured SMTP virtual server;
Address space: smtp destination.com, For Example: microsoft.com;

After all done, I can send email to the external party, and they will receive it;
But,
*if I have my router listen to port 25, and forward to 192.168.40.100 (default SMTP virtual server), and all incoming email are fine, except the needs to be connected external party, their email will be bounced, due to:
503 5.7.0 other side does not support STARTTLS  501 5.6.0 Data format error  

*If I pointed the router to 192.168.40.99 (the secured SMTP server) for port 25, then it will reject all email non encrypted.

Can experts help in here, how do I have normal email go to 100, and secured email from the said external party go to 99?

Thanks in advance.
0
mcclewan
Asked:
mcclewan
  • 2
  • 2
1 Solution
 
cyberaCommented:
For outgoing email, you need to create a new outgoing SMTP connector and specify the address space to the external party domain.
0
 
cyberaCommented:
Check out http://www.petri.co.il/configuring-exchange-2007-send-connectors.htm on how to configure send connectors
0
 
mcclewanAuthor Commented:
Thanks.  I already have the 2nd connector done, and outgoing reaches the other party.  Issue is incoming secured mail had bounced.
0
 
mcclewanAuthor Commented:
Found Problem.  It went through Spam Vendor before reach our exchange server.
0

Featured Post

Cyber Threats to Small Businesses (Part 2)

The evolving cybersecurity landscape presents SMBs with a host of new threats to their clients, their data, and their bottom line. In part 2 of this blog series, learn three quick processes Webroot’s CISO, Gary Hayslip, recommends to help small businesses beat modern threats.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now