This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mails in Mail Spool from Exchange and cant be released

Hello Guys,

 

we have a problem that incoming emails will be delivered to our exchange, but as soon as we set a smarthost from exchange to Sophos XG all emails will stuck in Mail Pool.

 

In log viewer we see only: Email has been accepted by Devcice and queued for scanning"

 

the Status is Failed with the Reason:  R=default_mx_router T=remote_smtp defer(110): connection timed out

 

or R=smart_hoist_route T=remote_smtp defer(110): connection timed out

 

 

we have restarted the device, tried to retry to send this emails no chance.

 

other system who are using XG as outgoind email relay, can send emails out without problems.

 

has anyone seeing something like that? what could be a solution here?

 

Thank you

 

 



This thread was automatically locked due to age.
Parents
  • Hi I have a similar problem (SFOS 18.0.0 GA-Build379.HF052220.1) with inbound mails that are delayed within the mail spool: The Mails should be routed to Exchange get stuck in mail spool with status "failure". After a retry, they are delivered but it taktes some time for the retry. I have no clue what is going on.

    They also get a timeout...

  • Could you try following? 

     

    Please use as Interface Criteria (outbound) your internal Interface to Mail Server. 

     

    Then retry. 

  • @LuCar Toni - thank you. I wil lets this work over night and take a look at the mail spool tomorrow. By now, it looks pretty good :-)

    I am trying to to understand what this NAT rule means.

    Do I understand this correctly that it means that any Mail-traffic form WAN side gets NATed to internal interface?

    Regards, Christian

  • Seems like in special cases, MTA is not able to use the LAN Interface and try to reach your internal Mail server with 0.0.0.0 as Source IP.

    As most products will drop such packets, they will never reach the Server.

    If you explicitly create a NAT Rule, which tells XG to use the Interface MASQ Rule, this issue seems not to happen. 

Reply
  • Seems like in special cases, MTA is not able to use the LAN Interface and try to reach your internal Mail server with 0.0.0.0 as Source IP.

    As most products will drop such packets, they will never reach the Server.

    If you explicitly create a NAT Rule, which tells XG to use the Interface MASQ Rule, this issue seems not to happen. 

Children