Solved

Enable StartTLS Exchange 2010

Posted on 2014-10-13
6
195 Views
Last Modified: 2015-11-30
I'm trying to get StartTLS enabled on my Exchange 2010 on Windows 2008R2
I have followed the steps in this link:
http://terenceluk.blogspot.com/2013/09/enabling-tls-for-exchange-server-2010.html
Locally, when I telnet to 25 and type "ehlo", I see STARTTLS listed.
Externally, when I do the same, STARTTLS is not listed.

I don't see any Event Viewer entries to show any errors.

I've read it possibly a firewall issue.  My Cisco engineer looked at the ASA and didn't see anything.  Even followed this link
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113336-asa83-mailserver-inside.html which I found from here:
http://www.expta.com/2014/03/troubleshooting-tls-smtp-connections-to.html

There is only one SSL Certificate which all services are using.  It was purchased from SSLS.com

What step am I missing?
0
Comment
Question by:NYTECJ
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 8

Expert Comment

by:tshearon
ID: 40377526
Do you have the ESMTP Inspection feature enabled on your ASA? If so you want to disable that and see if it works.
0
 

Author Comment

by:NYTECJ
ID: 40377542
Yes, ESMTP is disabled.  As per the link I mentioned above to Cisco.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40377611
If it works internally, then it should work externally as well.
The only reason I can think of that it would be different is on the Receive Connector configuration, that you have an additional connector configured for internal traffic only. If you have the two default connectors (Default and Client) and their configuration is default, then there is nothing else to do with Exchange. I would be pointing the finger at the Cisco.

Simon.
0
Office 365 Training for Admins

Learn how to provision tenants, synchronize on-premise Active Directory, and implement Single Sign-On with these master level course.  Only from Platform Scholar

 

Author Comment

by:NYTECJ
ID: 40406857
I'm sorry for not updating this as I should.  I'm having my Cisco engineer look at it.
0
 

Author Comment

by:NYTECJ
ID: 41341506
This was resolved.  Cisco equipment was upgraded to the latest firmware.  We now have it working.
0
 

Author Closing Comment

by:NYTECJ
ID: 41341525
It was the Cisco equipment.  Upgraded the Cisco to latest firmware.
0

Featured Post

Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
There are many Password Managers (PM) out there to choose from. PM's can help with your password habits and routines, but they should not be a crutch you rely on too heavily. I also have an article for company/enterprise PM's.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question