ScreenOS Firewalls (NOT SRX)
Reply
Ali
Regular Visitor
Ali
Posts: 7
Registered: ‎04-29-2008
0

Microsoft exchange 2007 mail routing problem

Hi All,

I am facing some abnormalities with my exchange server. Following is my topology diagram:

 

Mail1-----SSG-140----RadioBridge----SSG-140---Mail2

DC                                                                                  ADC

 

 

Both of these sites are part of a similar AD domain with sites configured with ADC. I cannot send email from Mail1 to Mail2 and vice versa. The messages are stuck in mail server's queue and the error message shown is as:

 

451 5.7.3 Cannot achieve exchange server authentication

 

I have tried configuring the permit all policy while ignoring the ALGs but that didnt resulted in anything good. There is no encryption between these sites and I can telnet from Mail2 to Mail1 on all exchange related ports.

 

Hope to hear some expert suggestions.

 

Regards,

 

Aly Zaigham

 

Distinguished Expert
spuluka
Posts: 2,551
Registered: ‎03-30-2009
0

Re: Microsoft exchange 2007 mail routing problem

I'm assuming this is a new setup and not a working situation what was migrated.  It sounds like the TLS setup is not correct.  In Exchange 2007 the communications between servers is all encrypted now.  So even though your clear connections to open smtp work the TLS connectors on the exchange transport need to be configured.

 

See this section of the troubleshooting guide at technet.

 

http://technet.microsoft.com/en-us/library/bb851506%28EXCHG.80%29.aspx

Steve Puluka BSEET
Juniper Ambassador
Senior Network Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.