We are seeing repeating messages in our Exchange 2000 server. All of the messages seem to come from listserv-type machines. Here's a log snippet of one:
ASL smtp proxy log:
2005:03:15-02:31:55 (none) exim[16221]: 2005-03-15 02:31:55 1DB6U3-0004Dd-5H H=infoworld.wc09.net [63.214.0.204] Warning: ACL "warn" statement skipped: condition test deferred:
2005:03:15-02:31:56 (none) exim[16221]: 2005-03-15 02:31:56 1DB6U3-0004Dd-5H enterprisewindows_91DF6D1B9F95B1EEA6E89068540A1B63@newsletter.infoworld.com H=infoworld.wc09.net [63.214.0.204] P=esmtp S=15833
2005:03:15-02:31:56 (none) exim[16225]: 2005-03-15 02:31:56 1DB6U3-0004Dh-Tv H=(cache.ohiobar.org) [10.1.1.96] Warning: ACL "warn" statement skipped: condition test deferred:
2005:03:15-02:31:56 (none) exim[16225]: 2005-03-15 02:31:56 1DB6U3-0004Dh-Tv <> H=(cache.ohiobar.org) [10.1.1.96] P=esmtps X=TLSv1[:D]ES-CBC3-SHA:168 S=9652 id=200503150701.j2F71fro016291@cache.ohiobar.org
2005:03:15-02:31:57 (none) exim[16525]: 2005-03-15 02:31:57 1DB6U3-0004Dd-5H => someaddress@ohiobar.org R=static_route T=static_smtp H=10.1.1.96 [10.1.1.96]
2005:03:15-02:31:57 (none) exim[16525]: 2005-03-15 02:31:57 1DB6U3-0004Dd-5H Completed
2005:03:15-02:41:56 (none) exim[17122]: 2005-03-15 02:41:56 1DB6dj-0004SA-VT H=infoworld.wc09.net [63.214.0.204] Warning: ACL "warn" statement skipped: condition test deferred:
2005:03:15-02:41:56 (none) exim[17122]: 2005-03-15 02:41:56 1DB6dj-0004SA-VT enterprisewindows_91DF6D1B9F95B1EEA6E89068540A1B63@newsletter.infoworld.com H=infoworld.wc09.net [63.214.0.204] P=esmtp S=15833
2005:03:15-02:41:56 (none) exim[17415]: 2005-03-15 02:41:56 1DB6dj-0004SA-VT => someaddress@ohiobar.org R=static_route T=static_smtp H=10.1.1.96 [10.1.1.96]
2005:03:15-02:41:56 (none) exim[17415]: 2005-03-15 02:41:56 1DB6dj-0004SA-VT Completed
Then the caching server's logs:
Mar 15 03:16:57 RedHat9 sendmail[17697]: j2F8Gvro017697: from=, size=15796, class=0, nrcpts=1, msgid=, proto=ESMTP, daemon=MTA, relay=asl.oh
iobar.org [10.1.1.10]
Mar 15 03:16:57 RedHat9 sendmail[17699]: j2F8Gvro017697: to=, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri
=31075, relay=10.1.1.37. [10.1.1.37], dsn=2.0.0, stat=Sent ( Queued mail for deliver
y)
Mar 15 03:26:57 RedHat9 sendmail[17918]: j2F8Qvro017918: from=, size=15796, class=0, nrcpts=1, msgid=, proto=ESMTP, daemon=MTA, relay=asl.oh
iobar.org [10.1.1.10]
Mar 15 03:26:57 RedHat9 sendmail[17920]: j2F8Qvro017918: to=, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri
=31075, relay=10.1.1.37. [10.1.1.37], dsn=2.0.0, stat=Sent ( Queued mail for delivery)
Our setup:
internet
|
asl 5.20
|
|- caching smtp server (linux, sendmail)
|
|- exchange 2000
Have any of you seen this behavior?
If so, what was the cause?
From looking at the logs,
All 3 machines have MX rec's and reverse DNS rec's. All 3 machines, if you telnet to port 25, you see the ASL smtp proxy introduce itself.
Any suggestions?
Thanks,
Shane
This thread was automatically locked due to age.