Jump to content

Recommended Posts

Posted

I am a bit confused here. We have Exchange 2007 on site and it has generally run alright for the years I've been here (it was in place when I arrived), and every now and then when we have a planned power outage, something seems to go wrong with it when it's powered down.

 

This time round, TLS has apaprently stopped working. When I try and email in from my gmail account I get told that "The error that the other server returned was: 454 454 TLS currently unavailable (state 8)." and it takes 24 hours for the message to arrive. This seems to be by design with regards to gmail, to alert to problems, although it was never a problem before.

 

When powering back up this time I removed the old domain controllers that had been demoted last week, so that may be relevant. I also deleted an expired Web Server certificate from the email server that had been issued by an enterprise CA that I destroyed a couple of weeks ago (it was easier than moving it from 2003 x86 to 2008R2 x64 given that no valid certificates were out).

 

Initially, after power up, Exchange wasn't accepting external emails - I could email around the organisation, I could email out, but nothing was coming in. I had to allow all permission groups on the Default and Client receive connectors to get that working again; no idea how it had worked in the past but this is a common theme with this Exchange server and power outages.

 

I've tried running Enable-ExchangeCertificate -service:smtp for the certificate the server currently uses (GoDaddy, for the OWA etc.) and Exchange tells me it is using that certificate for SIP.W (i.e. everything) but the TLS is still not doing anything.

 

Can anyone who actually knows something about Exchange shed any light on this? I'm just very confused that it worked before the power outage and doesn't anymore :(

 

(and yes, I am considering Office 365 in the new academic year, funny you should ask)

Posted
If I telnet to the server (telnet exchange 25) and send an EHLO it does tell me 250-STARTTLS so Exchange, at least, seems to think it's running. Whisky tango foxtrot?
Posted

are you saying you dont receive any external email or just email that requires tls?

 

up the logging on the default receive connector and repro the issue and check logs

  • Thanks 1
Posted
are you saying you dont receive any external email or just email that requires tls?

 

up the logging on the default receive connector and repro the issue and check logs

 

I receive external mail fine now - I wasn't, initially - but if I untick "Anonymous" under the permission groups for the Default Connector I get 530 5.7.1 Client was not authenticated errors from my Exchange server (and it is definitely my server, not the smart host). Authentication was set to TLS (and Mutual Auth TLS) only but adding Basic Auth to the methods still results in an error if Anonymous is unticked, whether or not the sub-option is checked or not (Offer only after starting TLS).

 

Gmail does eventually send the message through after 24 hours of trying to send it with TLS but it generates technical error messages first, which will scare people.

 

do you use a relay/smart host for incoming mail?

 

maybe this has the tls issue?

 

nick

 

We use our ISP's smart host but all this worked before, it's just stopped now. I can't see any details on the Gmail warning to give me a clue which server is generating the error, but I strongly suspect it's mine due to the symptoms above and the previous 18 months of no issues.

Posted

Having said all that... it's now working this morning. God only knows what's happened there, but right now, if it's working I'm happy.

 

Definitely time to move to Office 365 or actually start learning Exchange properly...

 

Thanks both.

Posted
Regardless of the TLS setting you have to have Anonymous ticked, otherwise how will Exch accept emails from the outside world unless you receive email from a hosted relay.
Posted
unless you receive email from a hosted relay.

 

Indeed we do, and Anonymous was never checked previously, but this is not a new songwhen it comes to this Exchange server; every now and then it randomly decides that the current configuration that has worked for years is no longer good enough. I didn't set it up initially, so who knows what's going on with it sometimes...

Posted
Indeed we do, and Anonymous was never checked previously, but this is not a new songwhen it comes to this Exchange server; every now and then it randomly decides that the current configuration that has worked for years is no longer good enough. I didn't set it up initially, so who knows what's going on with it sometimes...

 

What do you have on the network remote ip ranges? does that cover the hosted relays?

Posted
What do you have on the network remote ip ranges? does that cover the hosted relays?

 

Remote is set to 0.0.0.0-255.255.255.255 which I'm guessing - given that our MX record points to our smarthost - is probably unnecessarily generous and should be tightened up?

 

as @sukh says the default recieve connector has to have anonomous setting

 

I'm not doubting that it does - just that it seemed to work without it before, which is why I'm so confused!

Posted

Yes you can tighten to that relay server you receive your emails from.

 

There seems to have been a change made somewhere for that config to be changed.

  • Thanks 1
Posted

Tightened that range down to a single IP then, cheers.

 

It may be related to the demotion of old DCs or the removal of old CAs but frankly, if it works now, I'm happy, more pressing issues to hand for now I fear!

 

Cheers muchly.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...