Cannot validate Exchange Online connectors to On-premise exchange in a 365 Deployment

Hi Everyone,

I was wondering if anyone can help or advise? Unfortunately I feel i'm running out of ideas at the moment and so If anyone can help it would be very much appreciated

Recently I've setup an 365 hybrid deployment with exchange 2013 to use AD SSO for our VLE and to gradually move over our organisations users and decommission the exchange server.

Unfortunately I'm having difficulties getting the the Exchange Online connectors to communicate correctly with our on-premise. After using the Hybrid Deployment wizard the connectors are setup automatically but point to our council/ISP TMG server. As the connectors require a direct connection I have asked them to setup a public IP/address for our on-premise exchange server for the connector to use. When trying to validate this connector I receive the error log:

450 4.4.317 Cannot connect to remote server [Message=451 5.7.3 STARTTLS is required to send mail] [LastAttemptedServerName=*server*] [LastAttemptedIP=*ip*] [**]

There are Cisco routers but I have been advised that no SMTP inspection is taking place between any of the routers. Using telnet on my desktop to our on-premise shows that STARTTLS is there but when trying it from our Offsite backup server it shows the following:

250 - *on-premise exchange* hello [IP]
250 - SIZE 104857600
250 - DSN
250 - 8BITMIME

We have a Sonicwall NSA3600 firewall and I've gone through it with an engineer checking any security services that may be preventing it, I've updated firmware and turned off Deep Packet Inspection briefly on the chance it was the firewall but there are no settings I believe that are causing the issue.

Can anyone help/advise?


Marc GavinAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Todd NelsonSystems EngineerCommented:
Your firewall most likely is completely configured to permit mail flow between EOP and the on premises environment.  Take a look at this reference...

If the firewall is properly set up, then contact O365 support.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Todd NelsonSystems EngineerCommented:
Sufficient guidance provided for resolution.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.