Re: Exchange, SMTP queues and firewall
From: tcnolan (tcnolan_at_optonline.net)
Date: 06/22/04
- Next message: Morbid Angel: "Re: Version Choices"
- Previous message: Andy David - Exchange MVP: "Re: Exchange 5.5 Search"
- In reply to: Mark Arnold [MVP]: "Re: Exchange, SMTP queues and firewall"
- Next in thread: tcnolan: "Re: Exchange, SMTP queues and firewall"
- Reply: tcnolan: "Re: Exchange, SMTP queues and firewall"
- Messages sorted by: [ date ] [ thread ]
Date: 21 Jun 2004 17:22:58 -0700
Hi Mark,
Thanks for your reply. Today when I cleared out the queues in
Exchange, there were only 262 messages. So there really isn't that
many now. On Friday, when I started the SMTP server, in about 20
minutes I lost connection to the internet because the firewall ran out
of NAT ports.
We use Soho Watchguard (5.2.11) for our firewall. We kept losing
connection to the internet and whenever we rebooted the firewall, it
would be fine for a while. That is when we noticed in the firewall
logs the error NAT - Dynamic Translation Pool exhausted.
We have never had this problem before. We are a small office with
just 10 PCs. So we shouldn't have that many ports being used. The
tech support at Watchguard said the NAT ports should stay around 950.
They are as puzzled as we are.
I have used mutiple engines to scan for viruses and today changed all
the passwords on the server. When I turned off NDRs, the firewall
seemed to hold steady at 950 NAT ports available.
I don't know what you mean by "smarthost" but will look into it.
Thanks,
Terry
"Mark Arnold [MVP]" <mark@mvps.org> wrote in message news:<ne9ed0d9hchnr19m1n7o8ojhgd3bps2au8@4ax.com>...
> tcnolan@optonline.net (tcnolan) wrote:
>
> >Hi...
> >
> >
> How many NDR's do you have? If there are tons and tons you could be
> either a relay or being hit by spam in a big way.
> When exchange tries to send an NDR it will lookup the address and will
> only make a connection if it can get to the destination server. Having
> nDR's in the queue won't be taking up nat ports I wouldn't say. Do you
> really need to nat your outbound in this way though?
> Another consideration is to change the outbound connection to a
> smarthost rather than attempting delivery to each and every
> destination on the Internet. That will ensure that only one
> destination is available (usually the ISP's smtp relay) and will
> reduce connections, depending on what you actually mean by connections
> and depending on how the firewall is working.
>
>
> Mark Arnold MCSA MCSE+M MVP,
> FAQ: http://www.swinc.com/resource/exchange.htm
> Blog: http://www.msexchange.me.uk
- Next message: Morbid Angel: "Re: Version Choices"
- Previous message: Andy David - Exchange MVP: "Re: Exchange 5.5 Search"
- In reply to: Mark Arnold [MVP]: "Re: Exchange, SMTP queues and firewall"
- Next in thread: tcnolan: "Re: Exchange, SMTP queues and firewall"
- Reply: tcnolan: "Re: Exchange, SMTP queues and firewall"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|