CapnPugwash Posted November 20, 2015 Posted November 20, 2015 Hi, I'm performing a hybrid migration to O365 with an Exchange 2010 server. So far everything has gone well (Azure Diresync, Hybrid configuration manager etc) I've just had our ISP add the DNS records specified on the o365 domain verification page so that we can route our email through EOP but now I can't send emails to an external address I can send / receive internally I can send an email to an external address I don't receive any external emails (external senders do not get the email bounced back) I would assume this has something to do with the new MX record... I left the old one that points to our Exchange - could this be the issue?
CapnPugwash Posted November 20, 2015 Author Posted November 20, 2015 just tried to contact Microsoft Support through 365 portal , did a trace on one of the sent emails and got this response: We've found an issue Sorry, Office 365 received the message that you specified, but it hasn't been delivered to the recipient ([email protected]) yet. Unfortunately, it has been delayed. We're working on delivering it. This is the last record we have for the message: In process
CapnPugwash Posted November 20, 2015 Author Posted November 20, 2015 Hmmm, looking at the details of one of the pending emails it says: "450 4.4.101 Proxy session setup failed on Frontend with ‘441 4.4.1 Error encountered while communicating with primary target IP address: “Failed to connect. Winsock error code: 10061, Win32 error code: 10061.” Attempted failover to alternate host, but that did not succeed. Either there are no alternate hosts, or delivery failed to all alternate hosts. " Which looks like a firewall issue...
CapnPugwash Posted November 21, 2015 Author Posted November 21, 2015 Hopefully someone here can help me understand this a bit better. If I log into my O365 admin panel and try to validate the inward bound connector that points to my on-site Exchange server I get the error detailed in the post above. Searching the web for details on that error; everything is very specific - port 25 is blocked for inbound SMTP traffic. I've talked to Microsoft tech support and they say the same. We get our broadband from the LEA who work Mon-Fri 9-5 and we don't have access to this kind of thing, they have to sort it out for us. I won't be able to resolve this issue until Monday morning so I'm going to lose some emails (after 48 hrs non delivered emails are deleted/bounced back) Before Monday morning I'd like to get on top of this - is there anyway I can confirm that the above SMTP / Port 25 scenario is absolutely true? Could it be anything else? I don't have any issue sending or receiving emails or send ing emails to external addresses - I just cannot receive emails sent from external addresses. I'm abit confused by it as I lack don't really understand how email traffic works. Our Exchange server has worked fine for years so all SMTP traffic must have been coming through on port 25 or an alternative port... Is this info embedded in the send / receive connectors or is it controlled directly by the firewall? Hope someone can shed some light as I need to get this put to bed on Monday morning
CapnPugwash Posted November 21, 2015 Author Posted November 21, 2015 Now it's just getting ... weird. I have found ONE user who CAN receive ALL external mail!! How can the inward bound connector fail validation (from the o365 admin portal) but one user doesn't have any issues? I've just been on the phone to a microsoft tech guy, he had a look at one user where I had applied a license - he told me that this was the issue as licenses shouldn't be applied to users who have their mail box sat on the on-premise server. He was pretty adamant - but it's not the case. I can take an example user with no license applied (I haven't applied licenses to 99.9% of users). Send them a test email from an external account and it will end up stuck in a queue 'pending' This is making my head throb
vikpaw Posted November 21, 2015 Posted November 21, 2015 Sorry I can't help but I'm watching your progress. Keep trying, good luck.
CapnPugwash Posted November 22, 2015 Author Posted November 22, 2015 I think I've just slowly sent myself mental, which is never good. Partly because you miss the obvious. The user who is receiving external emails is ONLY getting them delivered to their O365 account. Not the on-premise Exchange mailbox (I had created them an o365 account - pre migration, to have a look at) This explains why I couldn't validate the inbound connector in the O365 admin portal AND they were receiving external emails - no mystery (phew) So, either my broadband is blocking SMTP traffic on port 25 or my MX records are incorrect... Does anyone know of any online tools I could use to test which of these might be the issue?
vikpaw Posted November 22, 2015 Posted November 22, 2015 I'm sure Microsoft had some tools for testing exchange. Also, is it defo port 25? It's not being encrypted into 465 or 587 is it? Might be ticked for encryption / secure / tls or something like that somewhere. Chances are the LEA is blocking it.
CapnPugwash Posted November 22, 2015 Author Posted November 22, 2015 I'm sure Microsoft had some tools for testing exchange. Also, is it defo port 25? It's not being encrypted into 465 or 587 is it? Might be ticked for encryption / secure / tls or something like that somewhere. Chances are the LEA is blocking it. I think it is the LEA blocking SMTP traffic. I was a bit weirded out by the fact that I can send external emails (why is the LEA not blocking outward bound SMTP traffic as well?) but thinking about it, Outward bound traffic sent from our local Exchange mailbox isn't being pushed through O365/EOP - only inbound traffic. That would make some kind of sense. In O365, Admin panel, If I try and validate the connector, it fails. If I look up the error message, most internet posts describe it as a firewall issue (SMTP traffic blocked) I guess I'll have to wait till Monday 9AM to find out!
ITGuyWestMidlands Posted November 22, 2015 Posted November 22, 2015 (edited) Try to telnet into your server. Before the migration surely you could receive smtp via port 25 to your exchange server? Edited November 22, 2015 by ITGuyWestMidlands
CapnPugwash Posted November 22, 2015 Author Posted November 22, 2015 I tried to telnet our mail server on port 25 & the operation timed out at the public facing IP address I then tried checking it using a port scanning web site and it came back with the message 'port 25 is closed on this server' So it definitely looks like it's our LEA is blocking the traffic or using an alternative to port 25 Hopefully it will get resolved in the morning
CapnPugwash Posted November 23, 2015 Author Posted November 23, 2015 All sorted! Sort of... Our ISP lease their service from RM - the incoming traffic is being blocked by them. They can resolve this but they need to know (a) what ports need opening (b) the O365 IP range To do this they charge £140 & if we have to change it again, they will charge us another £140! Turn around time can be 24hrs+ For now the easiest solution for me is to remove the O365 records from DNS so our email is routed as it was originally & I'll have to sort O365 when the school closes for Xmas.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now