Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Exchange 2007 temporary authentication error

Posted on 2011-04-28
5
Medium Priority
?
541 Views
Last Modified: 2012-05-11
We have 2 sites
Site A is HQ has single exchange 2007
Site B is sub-office with single exchange 2007
Site A & B connected by VPN.
Email flows from Site B to Site A over VPN then out to the world.
Email comes into site A travel over VPN to Site B
Was working fine then all of a sudden Mail stopped flowing to site B
Restarted exchange server went away
A week later it came back.
Queue filling up.
Site A could send email outside, but not to site B.
Queues reveal a  "4.7.0 Temporary Authentication Failure"
Restart site A server and problem vanished. Email flowed

To me it looks like Site B server is not not authenticating Site A, but not sure why it would do that.
Pretty much all I can find is when folk have big installs of exchange with roles spread onto different servers.
I did see soemthing about certification errors online, but would have thought that would just be a problem all the time.
A restart of Site A server seems to cure it so I can't see that being an issue.

Also not very sure on these receive connectors - exchange 2000 previously and this is very different,
so not quite sure how they work. Site A has 3 of them Client, Internalrelay & Site A Mail in, Site B has Client and Site B in
Both sites have Default disabled.


Any ideas?
0
Comment
Question by:Majicthise
  • 3
5 Comments
 
LVL 13

Accepted Solution

by:
Mohamed ElManakhly earned 1000 total points
ID: 35481729
anything in the Event viewer related to authentication ?
run EXBPA , any errors ?
0
 
LVL 13

Expert Comment

by:Mohamed ElManakhly
ID: 35481788
also check this post regarding FQD on the recieve connectors.

http://forums.msexchange.org/m_1800458339/mpage_1/key_/tm.htm#1800458349
0
 

Author Comment

by:Majicthise
ID: 35481866
I hang my head in shame.
Was looking at WRONG EVENT VIEWER!!
An internal transport certificate has expired.
How much clearer does that need to be?
0
 
LVL 13

Expert Comment

by:Mohamed ElManakhly
ID: 35482036
good luck :)
0
 
LVL 12

Expert Comment

by:GusGallows
ID: 37374319
I know this issue is closed, but I had a similar issue (same error) but a different solution and wanted to share it in case anyone else runs into this and it isn't the certificate. In my case, it wound up that the time on the exchange server that was queueing up was 5 minutes off from the domain controllers. That is too large of a differential. I found that the exchange server was set to use NTP to a DC that no longe existed. I changed it to use NT5DS, restarted the w32time service and the issue resolved.

To check the time service settings, you can do the following:

From Regedit:
Go to HKLM\SYSTEM\CurrentControlSet\services\W32Time\Parameters.
Make sure the type is set to NT5DS.
Close Regedit.
From Command Prompt, type Net stop W32Time && Net Start W32Time.

At this point you should see the time change on the server to the same time as the domain controller. You may need to restart your AD Topology service to get mail flowing again after doing this.

Hope this helps for those who are having this same issue.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Eseutil Hard Recovery is part of exchange tool and ensures Exchange mailbox data recovery when mailbox gets corrupt due to some problem on Exchange server.
Among the most obnoxious of Exchange errors is error 1216 – Attached Database Mismatch error of the Jet Database Engine. When faced with this error, users may have to suffer from mailbox inaccessibility and in worst situations, permanent data loss.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
Suggested Courses

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question