Solved

Exchange 2013 - unable to recieve external emails

Posted on 2016-11-11
14
61 Views
Last Modified: 2016-11-17
Hi Experts, have an issue where we are unable to recieve any external email. We had an existing email server and we added a new Exchange server. All URLs match for both servers and so do the certs. Today we made a change to firewall and externals DNS since IP address of new Exchange server has changed and now we are not receiving any external emails

Internal emails and sending emails to external domains is working fine

TIA
0
Comment
Question by:abhijitm00
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
14 Comments
 
LVL 15

Expert Comment

by:Jason Crawford
ID: 41883903
Where is the current MX record pointing?
0
 

Author Comment

by:abhijitm00
ID: 41883913
MX record points to Comodo Antispam gateway so there is no change there
0
 
LVL 15

Expert Comment

by:Jason Crawford
ID: 41883919
Have you tried running a message trace on the Comodo?  It would be helpful to know if it's ever received by an Exchange server or if it dies at the gateway.

What server is the Comodo handing off to?
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:abhijitm00
ID: 41883970
I am getting: Relay : exchange.domain.org:25
 Error code : 500
 Error message : SMTP host unreachable
 No entries on your request
0
 
LVL 15

Expert Comment

by:Jason Crawford
ID: 41884163
Ok did you add a firewall ACL and NAT for the Comodo IP on port 25?
0
 

Author Comment

by:abhijitm00
ID: 41884173
No there is no ACL for Comodo on the firewall. It is open to all IPs
0
 

Author Comment

by:abhijitm00
ID: 41884185
Just want to recap - Existing server name - mail.domain.org. All URLs point to mail.domain.org on both Exchange servers. New server name is exchange.domain.org. But cert has mail.domain.org as primary and exchange.domain.org and autodiscover as SANs.

All external DNS for autodiscover, mail.domain.org (via CNAME) point to exchange.domain.org which has a new external IP. NAT to old server mail.domain.org is stopped. At this time Activesync, Autodiscover and Outlook Anywhere stop working. Sending emails externally and internally work so does recieving emails internally, what does not work is emails sent from outside.

Would this have anything to do with FQDN name on recieve connectors or SSL certs?
0
 

Author Comment

by:abhijitm00
ID: 41884186
Also wanted to add to comment above that Comodo Antispam can't seem to connect to exchange.domain.org on port 25 although all firewall rules seem fine
0
 
LVL 15

Assisted Solution

by:Jason Crawford
Jason Crawford earned 500 total points
ID: 41884189
In that case you should be able to test access through the firewall by going to canyouseeme.org while logged on to the server receiving email from the Comodo and specify port 25.  Either that or you can try sending an email with PowerShell while off the network:

Send-MailMessage -From sender@domain.com -To recipient@domain.com -SmtpServer exchange.domain.com -Subject 'Testing' -Body 'This is a test'

Open in new window


If your firewall truly accepts all connections on port 25 that should at least make it to a Receive Connector.  While you're at it you should enable verbose logging on all Receive Connectors:

https://msdn.microsoft.com/en-us/library/bb124531(v=exchg.160).aspx
0
 

Author Comment

by:abhijitm00
ID: 41884310
Ok made some firewall changes and email is indeed flowing to new Exchange server.

Autodiscover and Outlook Anywhere is connecting but only after creating a new profile by manually adding server name. I have changed all URLs to point to exchange.domain.org and removed mail.domain.org from external DNS.
0
 
LVL 2

Expert Comment

by:MB Shaikh
ID: 41885176
Hi,

Once if you receive you external email at your Comodo Antispam gateway, then check your newly installed exchange server is accepting connections on port 25 from  Comodo Antispam gateway  vice versa  probably fire wall may be enabled on newly installed exchange server and in Comodo Antispam gateway you allow proper routing etc.

regards,
MB Shaikh.
0
 

Author Comment

by:abhijitm00
ID: 41885452
Android and iPhones are not able to configure using autodiscover. If I manually setup profile using server name I am able to connect. Outlook anywhere is working correctly. How can I fix autodiscover for phones? Currently i have autodiscover A record pointing to external IP of exchange.domain.org. There is also a _srv autodiscover record pointing to website, should i change this to exchange.domain.org?
0
 
LVL 15

Accepted Solution

by:
Jason Crawford earned 500 total points
ID: 41886632
Yes you only need public DNS record for Autodiscover.  The A record you currently have in place should be fine so remove the SRV.
0
 
LVL 15

Expert Comment

by:Jason Crawford
ID: 41892398
Glad I could help.  Take care :)
1

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question