Solved

Exchange server causing sonicwall to crash

Posted on 2011-03-20
10
793 Views
Last Modified: 2012-06-27
Hi,

I have an exchange server and one of the admins opened it up for anybody to connect and send email, i have (i think) locked it back down but it keep on flooding port 25 and router keeps crashing aswell as email, here is the log from the router

 Firewall Event The cache is full; 6144 open connections; some will be dropped 192.168.0.13, 16088, LAN (admin) 209.191.88.254, 25, WAN

is there anyway i can get it to stop?? i have ran malwarebytes it didnt find anything

thank you
0
Comment
Question by:jonathanduane2010
10 Comments
 
LVL 13

Expert Comment

by:Greg Hejl
Comment Utility
run wireshark to find out which IP is not closing connections to your mail server.

then block their traffic.

you may have a setting in your firewall for 'session timeout' for inactive connections

try decreasing this.
0
 

Author Comment

by:jonathanduane2010
Comment Utility
ok it was set to 15 mins i have set it to 2 mins

going to run wireshark now, but it looks like there are thousands of connections
0
 
LVL 13

Expert Comment

by:Greg Hejl
Comment Utility
See if inactive timeout can be set per port number - a global setting will affect your other services

look at your connections monitor for port 25 - sift by total packets and drop the connections that are not passing traffic

notice if these connections are coming from the same networks.  

also make sure you are using good RBL lists,  barracuda, spamhuas, spamcop are some favorites
0
 

Author Comment

by:jonathanduane2010
Comment Utility
the connections arent coming from the same network they seem to be the destination, the source seems to be the my local exchange server
0
 
LVL 13

Expert Comment

by:Greg Hejl
Comment Utility
i would try clearing smtp queue in exchange

malwarebytes has to be run in safemode - all the nastiest malwares detect all the malware scanners and pretty effectively hide themselves.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 4

Expert Comment

by:Tekyguy
Comment Utility
Check your mail queues, it maybe outgoing email - you may have a spam bot on one of your workstations inside your network.
0
 

Author Comment

by:jonathanduane2010
Comment Utility
where do i check the mail queues?
0
 
LVL 13

Accepted Solution

by:
Greg Hejl earned 125 total points
Comment Utility
0
 
LVL 8

Assisted Solution

by:dosdet2
dosdet2 earned 125 total points
Comment Utility
It sounds like your server is acting as an open relay and spammers are bouncing their spam off of your server.  If that is the case, your IP will soon be black-listed if it isn't already.

What version of Exchange are you running?

We've been there & done that.
We are running Exchange 2007 and we had to configure it to not relay messages and only accept outgoing email from our domain. (Can be a list of domains too, if you have several.)
Let us know.


0
 

Author Comment

by:jonathanduane2010
Comment Utility
i have exchange 2003, i have stopped relaying so relaying cant be done from the server
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Resolve DNS query failed errors for Exchange
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now