Re: Exchange and Reverse DNS - Here's a Challenge

anonymous_at_discussions.microsoft.com
Date: 04/28/04


Date: Wed, 28 Apr 2004 15:17:21 -0700

I was thinking of that - but I was wondering how this
would resolve the Reverse DNS lookup issue? When e-mail
goes out, won't it appear to come from the first interface
of the ISA Server? That's where it appears to come from
now and part of the reason we're having the Reverse DNS
issue

>-----Original Message-----
>My first question is why have two NIC's on your Exchange
Server? I would
>just have one internal NIC on your Exchange Server.
Publish your mail
>server with ISA Server using the Secure Mail Server
wizard. Your Reverse
>DNS PTR record should point to the external IP of the ISA
Server. This is a
>much more secure setup and will solve your Reverse DNS
lookup issues.
>
>--
>John Oliver, Jr.
>MCSE, MCT, CCNA, Exchange MVP
>Microsoft Certified Partner
>
>"Mike" <mikester209@yahoo.com> wrote in message
>news:5a2201c42d59$20d31460$a501280a@phx.gbl...
>> I'm having an interesting problem with my Exchange
Server.
>> I'm using an Exchange 2000 Server with two network
cards -
>> one connected to the internal network and one connected
to
>> the internet. The internal card is configured to use the
>> ISA server's internal address as it's Default Gateway
>> (making it a secure NAT client).
>> About a month ago, we started getting e-mails sent back
>> citing that there was No Reverse DNS entry for the
domain.
>> I did a search on DNS411.com and found that when I do a
>> reverse DNS lookup, it comes back with the proper domain
>> name and IP Address of the external card of the Exchange
>> Server. However, when I use the Exchange Server to go to
>> www.whatismyipaddress.com - it gives me the external IP
>> Address of the ISA Server - NOT the Exchange Server.
This
>> is where my Reverse DNS problem was coming from. I
removed
>> the ISA Server as the default gateway from the internal
>> NIC on the Exchange server and visited the site again -
>> this time it came back with the external IP Address of
the
>> Exchange Server. Problem solved right? - Wrong
>> After a few days, we noticed that mail was getting
backed
>> up in the queue. I tried everything from creating new
SMTP
>> Virtual Servers to trying to force mail out of the
queue.
>> I could not get mail back out to the internet until I
made
>> it a Secure NAT client again (made Exchange's default
>> gateway the internal IP Address of the ISA Server). And
>> now we are back to certain domains sending mail back
>> because of no reverse DNS entry.
>> Sooo - I'm up for any advice on this one. I thought
about
>> just publishing the Exchange Server with ISA, but I know
>> if that will solve the problem since Exchange will
remain
>> a Secure NAT client - and whatismyipaddress.com will
still
>> give me the first external address of the ISA Server.
>> Anyone have any ideas on what's going on and where I
>> should go next? Thanks in advance for the help!
>
>
>.
>



Relevant Pages

  • RE: Cant send or receive e-mail to POP3 users on same domain--HELP!
    ... Run the CEICW and go through the Internet and firewall option. ... If you choose to forward emails to the ISP's email server (smart ... Connector for POP3 Mailboxes' option, ... The Mailbox type is User Mailbox, and select the appropriate Exchange ...
    (microsoft.public.windows.server.sbs)
  • RE: Active Sync & OWA probelms
    ... Do you installed ISA server on your ... You have enabled Require SSL on the /Exchange virtual directory. ... In the right pane, click "Connect to the Internet", and then click ... forms-based authentication is required for Exchange Server 2003 ...
    (microsoft.public.windows.server.sbs)
  • RE: Catchall not working, EXTERNALLY?
    ... When I open the connection (over internet) to my exchange account, ... the data is stored on the Exchange server side. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange not receiving email from Internet
    ... Recieved email for that domain from internet. ... I understand that your exchange unable to ... permission to send to this recipient". ... The Exchange server Directory Access tab error may not related to ...
    (microsoft.public.windows.server.sbs)
  • Re: publications concerning port forwarding
    ... a postfix server in the DMZ and a MS Exchange ... services from the internet. ... The "OWA front-end in the DMZ using IPSec," comments were not on topic per ...
    (Pen-Test)

Loading