Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Exchange server causing sonicwall to crash

Posted on 2011-03-20
Medium Priority
Last Modified: 2012-06-27

I have an exchange server and one of the admins opened it up for anybody to connect and send email, i have (i think) locked it back down but it keep on flooding port 25 and router keeps crashing aswell as email, here is the log from the router

 Firewall Event The cache is full; 6144 open connections; some will be dropped, 16088, LAN (admin), 25, WAN

is there anyway i can get it to stop?? i have ran malwarebytes it didnt find anything

thank you
Question by:jonathanduane2010
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 13

Expert Comment

by:Greg Hejl
ID: 35175335
run wireshark to find out which IP is not closing connections to your mail server.

then block their traffic.

you may have a setting in your firewall for 'session timeout' for inactive connections

try decreasing this.

Author Comment

ID: 35175344
ok it was set to 15 mins i have set it to 2 mins

going to run wireshark now, but it looks like there are thousands of connections
LVL 13

Expert Comment

by:Greg Hejl
ID: 35175394
See if inactive timeout can be set per port number - a global setting will affect your other services

look at your connections monitor for port 25 - sift by total packets and drop the connections that are not passing traffic

notice if these connections are coming from the same networks.  

also make sure you are using good RBL lists,  barracuda, spamhuas, spamcop are some favorites
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 35175430
the connections arent coming from the same network they seem to be the destination, the source seems to be the my local exchange server
LVL 13

Expert Comment

by:Greg Hejl
ID: 35175465
i would try clearing smtp queue in exchange

malwarebytes has to be run in safemode - all the nastiest malwares detect all the malware scanners and pretty effectively hide themselves.

Expert Comment

ID: 35175549
Check your mail queues, it maybe outgoing email - you may have a spam bot on one of your workstations inside your network.

Author Comment

ID: 35176975
where do i check the mail queues?
LVL 13

Accepted Solution

Greg Hejl earned 500 total points
ID: 35177521

Assisted Solution

dosdet2 earned 500 total points
ID: 35181113
It sounds like your server is acting as an open relay and spammers are bouncing their spam off of your server.  If that is the case, your IP will soon be black-listed if it isn't already.

What version of Exchange are you running?

We've been there & done that.
We are running Exchange 2007 and we had to configure it to not relay messages and only accept outgoing email from our domain. (Can be a list of domains too, if you have several.)
Let us know.


Author Comment

ID: 35181140
i have exchange 2003, i have stopped relaying so relaying cant be done from the server

Featured Post

Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New style of hardware planning for Microsoft Exchange server.
On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit If you want to manage em…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question