?
Solved

Three Exchange servers on the same network, diff domains, can't send mail

Posted on 2013-06-24
1
Medium Priority
?
484 Views
Last Modified: 2013-07-07
We run a small IT shop.  In the building, we have our own exchange server, a hosted mail server for customer mail and a test mail server.

On the WAN side of the router, we have Comcast inbound with 15 static IPs and ATT inbound with 10 static IPs.  On the router, the Comcast is the primary with ATT as secondary.

Exchange1 has mail coming in from public IP xx.xx.xx.138 (Comcast)
Exchange2 has mail coming in from public IP xx.xx.xx.105 (ATT)
Exchange3 has mail coming in from public IP xx.xx.xx.109 (ATT)

Our problem was that mail coming in on 109 (ATT) was going out on 138 (Comcast) and that was giving us some grief for obvious reasons.  So, we wrote some policy rules in our firewall that forced traffic coming in on a public IP to go out on the same public IP.  However, when that rule is in place, Exchange3 cannot send mail to Exchange1.

Remove the rule and Exchange3 can send mail to Exchange1, but it goes out on the wrong public IP.  With the rule in place, everything is good, except Exchange3 cannot send mail to Exchange1.  We need to rule to make sure traffic leaves on the same IP it entered on.

Remember, all three Exchange servers are on the same 10.50.0.x network and we suspect that has something to do with it, but we are striking out homing in on the specific problem.

Ideas?

Thanks

Cliff
0
Comment
Question by:crp0499
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 39274122
You should have the servers send email between themselves directly, rather than trying to use public records and going out and back in again through the same firewall.

There are two ways to do this.

1. Split DNS for the MX record.
This is where you use an additional entry in the local DNS server of each server for the MX record for the other two servers.
For example, if the MX record mail.example.com, then you create a zone for mail.example.com then create a blank entry with the local IP address in it.

2. Send/SMTP Connector for each domain.
This bypasses the MX record lookup. You create a Send Connector for the other two servers. Set them to use a smart host, entering it in the format of [192.168.1.1]. On the Address space, enter the domain the remote server is responsible for.

Of the two, option 2 is probably the easiest and keeps everything in Exchange.

Simon.
0

Featured Post

Ransomware Attacks Keeping You Up at Night?

Will your organization be ransomware's next victim?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with our Ransomware Prevention Kit!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to install and use the NTBackup utility that comes with Windows Server.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
Suggested Courses
Course of the Month9 days, 19 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question