Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Possible 9.002 recepient rejection bug?

Not really sure where to begin on this one.  Been using v9.001 for a while now and email has been flowing great.  I did make a number of changes to my environment, after which time I can no longer receive email into my organization.  The Astaro (I still can't call it anything else) rejects with 550 550 Address unknown (state 13).  Here are the changes I made.  

1)  Created 2 additional DC's.
2) Created 2 additional Exchange 2010 Huub Transport servers.
3) Removed old DC's, giving the new DC's the same IP address.

At this point, mail was still flowing in while the Astaro was handing mail to the old HT server.  Tonight, I made these changes

4) Updated to v9.002.
5) Removed the old HT from the mail proxy and added the 2 new ones.  
6) Rebooted the Astaro, DC's, and HT's.

After this, I get the NDR.  I have verified in the Astaro's SMTP log that it is the one rejecting the email with address not found.  I have go to Definitions and users and verified and test user accounts.  I removed the old DC objects and readded them, both as definitions and as authentication servers.  I can test all aspects of AD lookups successfully from the Authentication servers tab.  It sees the user accounts and their email addresses.  I have flushed authentication cache.  Yet I still cannot get mail to go in.  Outgoing mail does work.  I changed back to having mail go into the old HT server, just to see.  No change.  Any ideas?


This thread was automatically locked due to age.
Parents
  • Good catch, Bruce!  I had totally forgotten about that tarpitting issue three years ago - didn't changing to AD also work?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • In the past I found AD lookups problematic at times, callout has always worked well so long as the mail server wasn't tarpitting lookups.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • In the past I found AD lookups problematic at times, callout has always worked well so long as the mail server wasn't tarpitting lookups.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?