Solved

Exchange Hybrid environment mail flow issue

Posted on 2016-07-18
10
57 Views
Last Modified: 2016-07-26
So here is the scenario:

- network with the following components: sonicwall NSA firewall, sonicwall email appliance
- on-premise Exchange 2013 server
- Office 365 account
- hybrid configuration wizard run successfully
- azure AD sync installed

We currently have the following mail flow conditions:
- MX records point to on-premise Exchange server
- mail flows to and from external email addresses from on-premise or O365 mailboxes
- mail flows from on-premise Exchange mailboxes to O365 mailboxes
- mail does NOT flow from O365 mailboxes to on-premise mailboxes

I can say that I have not updated the TXT records with the updated federation information (is that supposed to be internal and external DNS records?) but I am not sure if that is related.

Can anyone assist with troubleshooting this issue? I am not sure where to start.
0
Comment
Question by:twinstatevdv
  • 5
  • 5
10 Comments
 

Author Comment

by:twinstatevdv
Comment Utility
Also, all inbound email traffic on port 25 is routed through the sonicwall email appliance.
0
 
LVL 36

Expert Comment

by:Jian An Lim
Comment Utility
Rerun hybrid configuration wizard again

On Office 365, check it's outbound connector.
depends on version, you should have one outbound connector

try to test connectivity on that

you can run get-outboundconnector | fl and paste the result here
0
 
LVL 36

Accepted Solution

by:
Jian An Lim earned 500 total points
Comment Utility
one thing, email from Office 365 back to On-premise should not pass through sonic wall.
It must arrive directly
0
 

Author Comment

by:twinstatevdv
Comment Utility
What IP addresses and ports should I forward at the firewall direct to the exchange server? I know there is a set of EOP addresses.
0
 
LVL 36

Expert Comment

by:Jian An Lim
Comment Utility
0
Want to promote your upcoming event?

Attending an event? Speaking at a conference? Or exhibiting at a tradeshow? Easily inform your contacts by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

 

Author Comment

by:twinstatevdv
Comment Utility
THanks for the info! Which ports should I be forwarding?
0
 
LVL 36

Expert Comment

by:Jian An Lim
Comment Utility
port 25 for sMTP
port 443 for EWS and HTTPS
0
 

Author Comment

by:twinstatevdv
Comment Utility
got it, I will try that with the EOP addresses; my only concern is that we might be allowing non-hybrid email messages from Office 365 sources to bypass the email appliance.
0
 
LVL 36

Expert Comment

by:Jian An Lim
Comment Utility
non-hybrid email message?
the connector should only bring back any email that is mail user, nothing else.

also, you might want to upgrade your azure AD sync to AADConnect as the previous version have been deprecated.
0
 

Author Closing Comment

by:twinstatevdv
Comment Utility
Thank you for the assistance! Email appears to be flowing as desired.  :)
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
how to add IIS SMTP to handle application/Scanner relays into office 365.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now