?
Solved

asa 5540 unable to send or receive emails

Posted on 2014-03-16
16
Medium Priority
?
223 Views
Last Modified: 2014-04-02
Asa 5540 version 7.0(7) in front of exchange 2003 enterprise with the latest service pack, and GFI antispam box, queue builds up almost on daily basis, and we have to reload the firewall in order the get the email flowing, it works for a day then it happens again.
 no changes have happened since this started , we have relay taken care of already long time ago and we are good in that aspect. Also, smtp fixup is unchecked on the firewall.

I'm the only administrator in the company, I have not made any changes for the past 6 months not even patching the exchange server. and everything was working fine until 4-5 days ago.
0
Comment
Question by:Shando1971
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 9
  • 7
16 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39932879
That is classic FIXUP SMTP, so you need to check it is fully disabled.

Use one of the external services like mxtoolbox to confirm the SMTP banner. That will allow you to confirm if it is getting in the way or not.

Simon.
0
 

Author Comment

by:Shando1971
ID: 39932971
N toolbox says, smtp reverse banner ok.
What do you mean by fully disabled?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39933657
If you telnet in to port 25 on the server from a host external to your network, then do an ehlo you should get back a banner, and not an error.
Furthermore the verbs that are listed should not have any XXX in them. If they do, then the feature is still enabled.

Simon.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:Shando1971
ID: 39949462
Sorry, I couldn't reply back sooner, we had a death in the family.

when I try to connect to our mx records' ip address from outside, i got "Could not open connection to the host, on port 25", if I do smtp test on mxtoolbox i get "
Connecting to 173.161.x.y

220 server.companyname.com Microsoft ESMTP MAIL Service, Version: 7.5.7601.17514 ready at Sun, 23 Mar 2014 23:23:36 -0400 [617 ms]
EHLO MXTB-PWS3.mxtoolbox.com
250-server.companyname.com Hello [64.20.x.y]
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39950001
The fact that you are getting errors would tend to suggest that all is not well with the configuration of SMTP.

You need to do a telnet test so that you can see the full list of verbs when you do an ehlo.
You should get something back like this:

220 host.example.com Microsoft ESMTP MAIL Service ready at Mon, 24 Mar 2014 11
:28:03 +0000
ehlo
250-desktop.example.com Hello [192.168.1.101]
250-SIZE
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-STARTTLS
250-X-ANONYMOUSTLS
250-AUTH NTLM
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-XEXCH50
250-XRDST
250 XSHADOW


Simon.
0
 

Author Comment

by:Shando1971
ID: 39963265
do it from a workstation on the network you mean?
0
 

Author Comment

by:Shando1971
ID: 39963286
I got the following from inside the network;
250-server.mydomain.com Hello [192.168.6.x]
250-AUTH NTLM LOGIN
250-AUTH=LOGIN
250-TURN
250-SIZE 81920000
250-ETRN
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-8bitmime
250-BINARYMIME
250-CHUNKING
250-VRFY
250 OK
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39964065
Inside is no good, you need to test from an external host.
It should come back identical to what you have just posted.

Simon.
0
 

Author Comment

by:Shando1971
ID: 39966648
when I try to connect to our mx records' ip address from outside, i got "Could not open connection to the host, on port 25", if I do smtp test on mxtoolbox i get "
Connecting to 173.161.x.y
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39966748
That would tend to suggest that you have some kind of problem with the SMTP delivery - as it works internally that points the finger at the Cisco device.

Simon.
0
 

Author Comment

by:Shando1971
ID: 39966765
So, how can I fix the issue?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1500 total points
ID: 39967122
Do you have support on the Cisco device? If so, call Cisco. It is an issue outside of Exchange in my opinion, which means it is at the network layer. As the configurations can vary so widely you are best getting a specialist to look at the configuration.

Simon.
0
 

Author Comment

by:Shando1971
ID: 39967275
ok, thank you.
0
 

Author Comment

by:Shando1971
ID: 39967285
Hi,
any Cisco firewall experts can take a look at this please?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39967839
You will need to ask a new question in the Cisco zone, no one new will look at this question now - it doesn't work like a forum.

Simon.
0
 

Author Comment

by:Shando1971
ID: 39967857
ok, thank you.
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One-stop solution for Exchange Administrators to address all MS Exchange Server issues, which is known by the name of Stellar Exchange Toolkit.
On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question