Re: Moving to SMTP Email Connection

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I have now managed to get access via telnet, whilst connected to the router, by forwarding the port on the ISA server, so that at least now looks ok.

When I try from outside the network, I initally got an error saying Too many connections, but I have now just tried it again, and I can connect.

I have set up one of my domains (hardly used, but was using POP3 to check it) to have it's MX records adjusted at the ISP and connecting to that address also works now on telnet.

I have setup the SMTP connector to Request ETRN/TURN when sending, and at specified times, and added the domain in the Domains... button by Issue ETRN, however, when I start the SMTP service again, I get the following in the log. The domain name mentioned is my normal one, and not the one I am trying to test. The SMTP queue in Exchange Manager, then reports "retry" and "SMTP protocol error".

However, email messages appear after a while to spring to life and flash down the right route.

I then seem to end up with outgoing messages in the queue "Messages with unreachable destination".

There must be a problem somewhere, perhaps because it is only one domain setup this way?

----------------------------------------------------------------------------------------

212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 31, 0, 73, 0, 0, -, -, 220 auth.smtp.oneandone.co.uk (mrelayeu0) Welcome to Nemesis ESMTP server,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 31, 0, 4, 0, 0, EHLO, -, magiglo.co.uk,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 62, 0, 29, 0, 0, -, -, 250-mrelayeu0.kundenserver.de,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 312, 0, 12, 0, 0, -, -, 250-STARTTLS,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 359, 0, 4, 0, 0, EHLO, -, magiglo.co.uk,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 390, 0, 29, 0, 0, -, -, 250-mrelayeu0.kundenserver.de,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 640, 0, 12, 0, 0, -, -, 250-STARTTLS,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 640, 0, 4, 0, 0, EHLO, -, magiglo.co.uk,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 703, 0, 29, 0, 0, -, -, 250-mrelayeu0.kundenserver.de,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 859, 0, 12, 0, 0, -, -, 250-STARTTLS,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 859, 0, 4, 0, 0, EHLO, -, magiglo.co.uk,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:56, SMTPSVC1, SERVER1, -, 890, 0, 29, 0, 0, -, -, 250-mrelayeu0.kundenserver.de,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1078, 0, 12, 0, 0, -, -, 250-STARTTLS,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1078, 0, 4, 0, 0, EHLO, -, magiglo.co.uk,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1125, 0, 29, 0, 0, -, -, 250-mrelayeu0.kundenserver.de,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1187, 0, 12, 0, 0, -, -, 250-STARTTLS,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1187, 0, 4, 0, 0, EHLO, -, magiglo.co.uk,
212.227.15.179, OutboundConnectionResponse, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1218, 0, 50, 0, 0, -, -, 421 auth.smtp.oneandone.co.uk repeat limit reached,
212.227.15.179, OutboundConnectionCommand, 5/29/2008, 10:07:57, SMTPSVC1, SERVER1, -, 1218, 0, 4, 0, 0, QUIT, -, -,



"Joe" <joe@xxxxxxxxxxxxxx> wrote in message news:e2oTm%23MvIHA.3680@xxxxxxxxxxxxxxxxxxxxxxx
Neil Jordan wrote:
Although I have had a few problems with that, when I did it, and tried a telnet to port 25, the ISA server recognised it (via the logging option), but seemed to close the connection. No errors reported, but the telnet command never completed.

I got this in the log in case it is of help

Log type: Firewall service
Status: A connection was abortively closed after one of the peers sent a RST segment.
Rule: SBS Smtp Server Access Rule


Which at least is presumably different to the situation when you try from outside. Unfortunately, I get the impression that there are no ISA experts here. I'm certainly not one: every so often I need to learn enough to fix a particular issue, then six months later it's all gone. Use it or lose it, and I've never had anything to lose concerning the business of getting SMTP in.

My feeling at this point is that there may be two separate issues, one of getting into the network on port 25 from outside, and possibly an ISA one, though it's also possible that ISA is by default supposed to refuse connections from machines in the 'outer' network. All I can suggest is that you have a look at the access rule it mentions, and see if it's obvious how to make sure that an outer network machine can connect. I don't currently have access to an ISA-equipped SBS. Once you get a telnet session going, that's at least half the battle.

The connection from outside issue is only really resolvable either with a definite statement from the ISP that they don't block 25 (with most ISPs you'll have trouble talking to someone who knows what ports are) in which case you have router problems, or the use of a router with logging facilities.

Sorry I can't be of more help at the moment.

.



Relevant Pages

  • Re: New protocol rules dont seem to work
    ... > I just took the existing protocol definition for telnet and enabled it ... Yet they can ping the telnet server through ISA. ... >> connections from ISA server, you should create appropriate IP Packet ...
    (microsoft.public.isa)
  • Re: VPN Help needed
    ... I suspect that the ISA ... firewall is not the problematic piece in this problem. ... I've setup ISA Server 2004 to accept outbound PPTP connections. ...
    (microsoft.public.isa.vpn)
  • Re: Strange NAT problem with outbound FTP connections
    ... I have the ISA server behind another permiter hardware firewall. ... connections from internal hosts were going through the ISA server without NAT ... The perimeter firewall would then see the private IP address ...
    (microsoft.public.isa)
  • Re: 127.0.0.1 Anonymous
    ... All browser connections begin as anonymous and ISA logs everything it sees, so you'll see these connections in the ISA logs. ... I`m getting every time at my isa server 2000 a web conection ...
    (microsoft.public.isaserver)
  • Re: Telnet via ISA Trouble...
    ... > Don't telnet or do anything from the ISA firewall itself. ... Just installed ISA server on a fresh box. ... I have created a Protocol Rule allowing all internal Internet users to ...
    (microsoft.public.isaserver)