ScreenOS Firewalls (NOT SRX)
Showing results for 
Search instead for 
Do you mean 
Reply
Highlighted
Ali
Regular Visitor
Posts: 7
Registered: ‎04-29-2008
0 Kudos

Microsoft exchange 2007 mail routing problem

Hi All,

I am facing some abnormalities with my exchange server. Following is my topology diagram:

 

Mail1-----SSG-140----RadioBridge----SSG-140---Mail2

DC                                                                                  ADC

 

 

Both of these sites are part of a similar AD domain with sites configured with ADC. I cannot send email from Mail1 to Mail2 and vice versa. The messages are stuck in mail server's queue and the error message shown is as:

 

451 5.7.3 Cannot achieve exchange server authentication

 

I have tried configuring the permit all policy while ignoring the ALGs but that didnt resulted in anything good. There is no encryption between these sites and I can telnet from Mail2 to Mail1 on all exchange related ports.

 

Hope to hear some expert suggestions.

 

Regards,

 

Aly Zaigham

 

Distinguished Expert
Posts: 4,300
Registered: ‎03-30-2009
0 Kudos

Re: Microsoft exchange 2007 mail routing problem

I'm assuming this is a new setup and not a working situation what was migrated.  It sounds like the TLS setup is not correct.  In Exchange 2007 the communications between servers is all encrypted now.  So even though your clear connections to open smtp work the TLS connectors on the exchange transport need to be configured.

 

See this section of the troubleshooting guide at technet.

 

http://technet.microsoft.com/en-us/library/bb851506%28EXCHG.80%29.aspx

Steve Puluka BSEET
Juniper Ambassador
Senior IP Engineer - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
JNCIA-Junos JNCIS-SEC JNCIP-SEC JNCSP-SEC
JNCIS-FWV
JNCDA JNCDS-DC JNCDS-SEC
JNCIS-SP
ACE PanOS 6
http://puluka.com/home