Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Microsoft 2003 SMTP as relay with Exchange 5.5

Status
Not open for further replies.

Justyn

Instructor
Oct 22, 2003
28
US
Ok guys,

I have a weird on that I can not solve, so I am posting it here since the current environment is 5.5. We are going to be upgrading a customer to Exchange 2003 shortly; however, their current mail relay server is an Exchange 5.5 talking to an Exchange 5.5 server on the backend. The customer wants to replace the relay first with a server running Windows 2003 with the native SMTP services rather than using Exchange in the new DMZ.

The SMTP relay works great for all incoming messages, routes perfectly actually, however, on the outbound side it will send every message except for mail that is destined for its own domain.

The problem as I see it is the PIX firewall they have and the DNS. The DNS entry for the domain (say xyz.com) points to an external IP on the live internet. When the SMTP server in the DMZ (a 192.168 address) does a lookup for the xyz.com domain it gets the external address and the PIX won’t let it go out and back in on the interface since it thinks it is being spoofed or hacked.

Can anyone think of a way to get it to not do a lookup and send it straight to the internal Exchange server?

I have tried all of the normal things like trying to point it back using a “Smart Host” entry in the virtual SMTP server entry.

Any help would be appreciated.

Thanks,
Justyn


Justyn Worrell
MCP, MCSE, MCT, CCA, CCEA, CCI
SCSA, CCSA, CCSE, CCNA, AANG-UP
 
I guess I'm missing something but if you have the Exchange server set to accept mail to xyz.com as inbound how is any even getting to the SMTP server as outbound?
 
The exchange server is set to forward Internet E-Mail to the old relay server (or the new one now) and some of the UNIX systems using sendmail are putting the full internet address (john.doe@xyz.com).

Thanks,
Justyn

Justyn Worrell
MCP, MCSE, MCT, CCA, CCEA, CCI
SCSA, CCSA, CCSE, CCNA, AANG-UP
 
If i have this straight...The relay server sits in the DMZ. Inbound mail, (mail not from xyz.com) comes in through the DMZ into the relay server then forwards the mail to the internal if you will, exchange server. I do not quite understand how mail from xyz.com goes out let's say to a hotmail recipient. Does the internal exchange server(not the relay server) send mail back out to the relay server and that sends it out to its intended recipient? Or does the exchange server that is not in the DMZ pass the mail out itself to the world. If your problem is outbound mail, why not have the back end server send the mail that is out bound directly? on the backend server set it to use DNS for outbound. And Change the DNS entry to an internal dns server provided there is one. Sorry if I dont make total sense but we had the same issue once and were able to fix by setting up an internal DNS server and having the backend server use that to send outbound mail. Inbound mail comes into our relay server then forwarded to our back end server. Outbound mail goes directly out of our backend exchange server. Hope this helps..
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top