2008R2 Connection Broker internal vs external name and UCC Certificates

I have a RD Farm, all in 2008R2.  Consisting of Gateway, Connection Broker, multiple Session Hosts.  They belong to an AD Domain, xyz.local.  The machines have AD names, CB.xyx.local, GW.xyz.local, SH1.xyz.local, SH2.xyz.local.
The internal DNS system has a Zone for the External Domain, MyDomain.com.  There are host records for the farm, rdpfarm.mydomain.com pointing to the Internal IP of the farm.
The farm is accessible on the Internet at rdpfarm.mydomain.com via Public DNS.
We have a VeriSign Public UCC Certificate, that has the public MyDomain.com SAN's for the hostnames for all the machines,  CB.MyDomain.com, GW.MyDomain.com, SH1.MyDomain.com, SH2.MyDomain.com, and the farm name is the Common Name rdpfarm.MyDomain.com. 
(Note, as of soon, internal Domain names are no longer allowed on UCC Certificates)
I have tried everything I can find to get the Gateway and/or the Connection Broker to answer using the rdpfarm.MyDomain.com name and match the Certificate, without success.
As I recall in Exchange Server we face a similar problem, but there is a method in Exchange to cover this.  If there is one for an RD farm, I cannot find it.
Any help here would be greatly appreciated.

Hi,
Thank you for posting in Windows Server Forum.
Did you receive any particular error during\event id this issue?
For certificate, here is requirement for RDS server which need to have for successful configuration.
Basic requirements for Remote Desktop certificates:
1. The certificate is installed into computer’s “Personal” certificate store. 
2. The certificate has a corresponding private key. 
3. The "Enhanced Key Usage" extension has a value of either "Server Authentication" or "Remote Desktop Authentication" (1.3.6.1.4.1.311.54.1.2). Certificates with no "Enhanced Key Usage" extension can be used as well. 
In Windows 2008/2008 R2, you connect to the farm name, which as per DNS round robin, gets first directed to the redirector, next to the connection broker and finally to the server that will host your session.
Please check below article for information.
a. Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services
b. Configuring Remote Desktop certificates
c. Dealing to the annoying certificate errors and multiple credential
requests in Remote Desktop Services 2008 R2
Hope it helps!
Thanks.
Dharmesh Solanki
TechNet Community Support

Similar Messages

  • Scan to Email Error Message "cannot connect to server. check server name and address"

    I have a HP Officejet Pro 8600 Plus. 
    I've been using this printer for several months.  Now am getting an ERROR message when I try to scan to email that it "cannot connect to server. check server name and address" 
    I'm not sure how to check this.  We can all still print remotely via the internet connection. 
    Anyone have any ideas?

    Thanks for the info.,
    Did you recently change your operating system or network router that started to cause this error?
    Check out this thread - http://h30434.www3.hp.com/t5/Scanning-Faxing-and-Copying/Configuring-quot-Scan-To-E-mail-quot-on-HP-...
    You may also need to change the printer DNS settings manually - http://h30434.www3.hp.com/t5/Printer-All-in-One-Install-Setup/HP-8500-Scan-to-Email-setup-cant-conne...
    Thanks

  • Connect an ipod to external speakers and amplifer

    how can i connect an ipod to external speakers and amplifer

    Rex,
    Since the toslink is optical, the 3.5mm adapter will not work for you as it is only ment as a conversion to a mini-toslink cable. Your first option of using the DAC, is in my opinion the best and perhaps only way to get audio out without going to a fancy amp or tuner first.
    One option that I'm considering is the Bose Solo TV sound system. It might set you back about 4-Grant's, but I generally enjoy the sound of bose for most music/tv/movie purposes; and it has a direct optical audio input that you can run either from your tv or your ATV. Whatever audio you're sending to your TV via the HDMI, should go to these speakers through your HDTV's toslink output with equal digital clarity.
    I've read a few other posts on the apple discussion forum which lead me to believe that the optical output of the ATV might not work so well after the 5.2 update... so whatever I do, it won't be JUST for use with the ATV.

  • How do I connect Apple TV to external speakers and my TV?

    I just bought an Apple TV for my studio apartment and have it connected to my TV via HDMI, and use AirPlay to stream my music and videos. Video works great, but the my TV's internal speakers are low quality. So, I would like to have my audio come from external speakers (which I have not bought yet), for the following 2 scenarios:
    Listening to music via AirPlay, preferably without having to turn my TV on.
    Watching videos on my TV, with the audio coming through my external speakers rather than the TV speakers
    I see my Apple TV has an Optical Audio (Toslink) port, but the salesperson at the nearby electronics store said none of their speakers have Toslink cables, only 3.5 mm (or USB). The only solution I found is an AV receiver box that has optical input but costs hundreds of dollars. I am looking for something cheaper and am willing to settle for "pretty good" sound quality.
    Is there another way to get this to work?
    This article recommends using a digital audio converter (DAC) to connect the Apple TV to a stereo amplifier. This seems like it would satisfy scenarios (1) and (2) above.
    Also, I found this "Toslink to 3.5 mm adapter" for a few bucks; could I just plug that into my Apple TV and then connect it to any speakers (like computer speakers) with 3.5mm input?
    Any ideas would be appreciated.

    Rex,
    Since the toslink is optical, the 3.5mm adapter will not work for you as it is only ment as a conversion to a mini-toslink cable. Your first option of using the DAC, is in my opinion the best and perhaps only way to get audio out without going to a fancy amp or tuner first.
    One option that I'm considering is the Bose Solo TV sound system. It might set you back about 4-Grant's, but I generally enjoy the sound of bose for most music/tv/movie purposes; and it has a direct optical audio input that you can run either from your tv or your ATV. Whatever audio you're sending to your TV via the HDMI, should go to these speakers through your HDTV's toslink output with equal digital clarity.
    I've read a few other posts on the apple discussion forum which lead me to believe that the optical output of the ATV might not work so well after the 5.2 update... so whatever I do, it won't be JUST for use with the ATV.

  • P1102W wifi connection requires SSID pluss user name and password to connect

    Hello Community.
    I had investigate how to connect my P1102w printer to the wifi and it is easy but here is the problem.
    I have no problem searching with Printer wifi config my WIFI SSID. (usb printer plugged) but My connection requieres when SSID found a user and a password.
    I have not find where does the printer have the option to set up my user name and password to login in the needed SSID.
    Can sombody help me.
    Thanks.

    Yes, but the method is to simply connect the TC to the computer by ethernet and use it on a separate network. That is the best way to do it.. but you can also do the same thing better and easier with an external hard disk plugged in. For a desktop computer this is a better solution in a way. You will only be using the TC for Time Machine backups anyway.
    If you want to continue to use the TC.. then the actual network settings I put in this thread with a whole series of pictures.
    https://discussions.apple.com/thread/4817218?tstart=30
    If you cannot follow any of that just ask.

  • RV 120W:How to block device from connected to interner through device name?

                       Hi guys,
    i am using the router,rv 120w
    can i block device from connected to internet through device name?
    for example,the Android Phone wil always has "android" in their device name.How can i block the device which has "android" in their device name from link to internet?
    Thanks.

    Good morning
    Thanks for using our forum
    Hi Louis, my name is Johnnatan and I am part of the Small business Support community. You can´t block any device by the name, however you can block devices using it mac-address. Go Firewall> Access Control>Mac Filtering in this section you can specify the mac address of  the devices and block them.
    I hope you find this answer useful,
    *Please mark the question as Answered or rate it so other users can benefit from it"
    Greetings,
    Johnnatan Rodriguez Miranda.
    Cisco Network Support Engineer.

  • Itunes can't connect to internet, istore, track names and not working properly

    Help please I have spent hours trying to sort out what ever is wrong with my itunes.
    I can't connect to store when trying to take digital copies of dvd, I can't get track names, When I connect ipad and iphone it doesn't go past backing up.
    I have been in communication with Norton and they have tried loads of things. I have now uninstalled it until I get to the route of this problem.
    Please help me!!

    OK many are not aware of this, but Windows XP with SP2 comes with windows firewall automaticcly on. so first check to make sure you have windows firewall off. goto the control panel, select "Security centre" and make sure it is tuned off. If the security center says "On" and is lited up green, you have some firewall on.
    You may want to check with your ISP and make sure there not blocking you from the music store too thru there own firewall or other means

  • Server 2012 R2 Remote Desktop Connection Broker, Server Name Change.

    We have a server that was the connection broker, We changed its name and now the connection broker wont recognize the new name.  It continutes to want the old server.  Unfortunately we cant change it back.  Is there a fix for this? 
    We tried the powershell command but it doesnt see the old server name and errors out.

    Hi,
    Changing the name of a RD Connection Broker server is not supported.  If you are able to remove RD Connection Broker Role Service and install a new RDS deployment you may be able to get it working again (with perhaps a few registry fixes),
    but you will lose all of the configuration data associated with your deployment.  If you have a very basic RDS deployment it may not be a big deal to recreate the collections, configure settings, publish
    RemoteApps, etc., as they were before.
    Another potential option if you were able to temporarily change the name back would be to switch to HA mode with the database stored on the local server (in SQL Express), add another RDCB server, remove RDCB from the original (leaving the SQL Express database
    still functional), rename the server, add it back as a RDCB server, then remove RDCB from the second server.  I have not tried this procedure but at first glance I believe it should work, although it may be a bit complicated if you are not well versed
    with 2012 R2 RDS.
    If this is a small environment you may want to consider backing up any data on the servers and then reinstalling all of the RDS servers from scratch.  
    It is possible to manually fix the issue you are seeing by editing the RDMS database, editing the registries of all the RDS servers, and other related tasks, however, I would not suggest it due to the complexity.
    -TP

  • SQL EXpress Server 2012 Installed in VM for RD Connection Broker

    All,
    I have big trouble now...
    I have 2 cluster machine and created one Virtual Machine in the cluster and installed SQL Server Express 2012 in VM.
    In both cluster machine installed SQL Client 11.0.  and RD Connection Broker installed one of the Cluster machine, while configure RD HA it throws error Please refer screen shot.
    Is it right to install SQL server on Virtual Machine ?
    Is it possible SQL Server 2014 Standard installed one of the cluster machine and RD Connection Broker enable both cluster machine and make HA of RD Connection Broker HA ?
    What is the best way to achieve to enable RD Connection broker with in Cluster machine(2 Node) ?
    Please any one guide to us.
    Regards
    Venki

    Hi Venki,
    Thank you for posting in Windows Server Forum.
    Generally the error which you are facing occurs due to permission and security issue on SQL server. we need to specify the permission during RDCB setting.  Here suggest to create the database manually and check the result.
    CREATE DATABASE 'rds_db'
    Where rds_db is the database specified in your connection string
    DRIVER=SQL Server Native Client 11.0;SERVER=<SQL Server Name>;Trusted_Connection=Yes;APP=Remote Desktop Services Connection Broker;DATABASE=<DB Name>
    Grant DBO permissions to the service account on the RDS server and try to run your wizard again.
    Also when configuring RDCB HA, we need to create a local folder to store database which is “Remote SQL file systems”. And if local path is used create a folder on the root directory of the SQL Server (C:\RDCB).
    Please check below article for more information.
    Deploying RD Connection Broker High Availability in Windows Server 2012
    http://ryanmangansitblog.com/2013/03/30/deploying-rd-connection-broker-high-availability-in-windows-server-2012/
    RD Connection Broker HA – SQL Permissions
    http://microsoftplatform.blogspot.com/2012/04/rd-connection-broker-ha-sql-permissions.html
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • Outlook Anywhere: internal working, external not

    Hi,
    I posted a similar question relating to home users and authentication
    here, but this question is different
    I am in co-existence with Ex2010 and about to start moving mailboxes onto Ex2013. I already have a few test mailboxes on Ex2013. I am running through a final check list of items to test but before I point my internal and external DNS to Ex2013 I am simulating
    this from a laptop by changing the hosts file. Everything is working fine with the exception of users outside my network who use Outlook Anywhere.
    This is what I know...
    Internally Outlook works fine for mailboxes on both Ex2010 and Ex2013, as does access to public folders, etc
    If I create a new mail profile for a mailbox user already on Ex2013, Outlook connects fine.
    If I create a new mail profile for a mailbox user on Ex2010, autodiscover works and fills in the fields, but Outlook cannot logon. I get "The action cannot be completed. The connection to Microsoft Exchange is unavailable. Outlook must be online or
    connected to complete this action."
    If I edit my hosts file and point back to Ex2010 CAS then the mail profile will be created successfully and Outlook opens. Changing the hosts file back again breaks Outlook. 
    Here are my settings:
    Ex2010
    ExternalHostname: webmail.company.co.uk
    InternalHostname: {empty}
    ExternalClientAuthenticationMethod: Ntlm
    InternalClientAuthenticationMethod: Ntlm
    IISAuthenticationMethods: {Basic, Ntlm}
    ExternalClientsRequireSSL: True
    <mark>InternalClientsRequireSSL: False</mark>
    Ex2013
    ExternalHostname: webmail.company.co.uk
    InternalHostname: webmail.company.co.uk
    ExternalClientAuthenticationMethod: Ntlm
    InternalClientAuthenticationMethod: Ntlm
    IISAuthenticationMethods: {Basic, Ntlm, Negotiate}
    ExternalClientsRequireSSL: True
    InternalClientsRequireSSL: True
    Get-OutlookProvider
    EXCH: CertPrincipalName: msstd:webmail.company.co.uk
    EXPR: CertPrincipalName: msstd:webmail.company.co.uk
    In IIS...
    Ex2010
    RPC (Default Web Site) - Authentication
    Basic Authentication = enabled
    Windows Authentication = enabled
    <mark>Authentication Providers order:
    1. NTLM
    2. Negotiate</mark>
    Ex2013
    RPC (Default Web Site) - Authentication
    Basic Authentication = enabled
    Windows Authentication = enabled
    <mark>Authentication Providers order:
    1. Negotiate
    2. NTLM</mark>
    So, Ex2013 appears to not be proxying connections to Ex2010 mailboxes when outside my network. As mentioned, internally this setup works fine. And connecting to mailboxes on Ex2013 (so no proxying) also works fine.
    Some settings, such as Ex2010 InternalHostname and the order of authentication providers in IIS are different between the two servers. Would this make a difference?
    Q. Should I have an explicit entry in 'InternalHostName' on Ex2010?
    Q. On Ex2013 I have tried putting NTLM above Negotiate, which did not make a difference, and also reverted back automatically after a few minutes.
    Many thanks for any comments and suggestions

    Hi Off2work,
    My setup is fairly simple. A single all-in-one Ex2010 server and single all-in-one Ex2013 server.
    I am using a Sonicwall NSA 3500. Setup with NAT rules for port 443 to Ex2010 server. Not using reverse proxy or TMG.
    99% of mailboxes are still on Ex2010.
    Internal DNS (for webmail.company.co.uk) points to internal IP of Ex2010
    External DNS (for webmail.company.co.uk) points to external IP on Sonicwall.
    Its worth mentioning that internal Outlook users are currently using RPC, not Outlook Anywhere (RPC over HTTP). I'm yet to turn this on. It does work however as I have tested it.
    External users (non-domain) are obviously using RPC over HTTP from Outlook Anywhere.
    What I am doing is 'simulating' pointing webmail.company.co.uk to Ex2013. I have a laptop I am testing this from. I can simulate this on the LAN by editing the hosts file. Users with mailboxes on Ex2010 can create Outlook profiles and access their mailboxes.
    Same for users on Ex2013 - it works fine. 
    To simulate this from outside the LAN I have the laptop connect from a known external IP and I setup a custom NAT rule to forward to Ex2013. From 'outside', users with mailboxes on Ex2013 can create a profile fine. Users with mailboxes on Ex2010 cannot.
    The autodiscover part works and fills in the fields, but the Outlook cannot logon to the mailbox. I get the message shown on my very first post.
    From my untrained point of view, this appears to be an authentication issue when the Ex2013 server is proxying to the Ex2010 server.
    To answer your other questions, I never setup a CAS Array in 2010 as I only had 1 server. I now read this would have been advised. Still the output for your command returns (from Ex2010)
    DB1 Ex2010.company.local
    DB2 Ex2010.company.local
    etc
    etc
    As mentioned, current internal Outlook users are using RPC so connect to this address. When I enable RPC over HTTP they will connect to webmail.company.co.uk
    One question, in Ex2013, in IIS, for Windows Authentication > Providers, I have Negotiate above NTLM. How do I switch this around so it matches Ex2010? I can do it manually, but it keeps reverting back.
    Thanks very much.

  • Trying to simply connect to Oracle with VBscript/ASP - and I cannot.

    This is rather embarrassing. I am pretty fluent with ASP and VBscript, and I have written many a web application connecting to Microsoft SQL Server. Now I have a need to connect to an Oracle database, and I'm beating my head against the wall.
    1) Web server is Windows Server 2003 SP1
    2) Using ASP (not ASP.NET) & VBscript
    3) I have installed the Oracle drivers on the server - it is version 10g
    4) The administrator of the Oracle database to which I want to connect has created a username and password for me to use from within my code
    5) Here is the code I am trying to run:
    Set objConn = Server.CreateObject("ADODB.Connection")
    objConn.Open "Provider=MSDAORA;Data Source=XXXXXXX;User Id=YYYYYYY;Password=ZZZZZZZ;"
    That's it. 2 lines of code just trying to establish a connection. Using the user name and password provided to me by the administrator, and for Data Source I am using the IP address of the Oracle server (like I have done in the past when connecting to SQL Server). I receive the following error message when viewing this in a browser:
    Microsoft OLE DB Provider for Oracle error '80004005'
    ORA-12154: TNS:could not resolve the connect identifier specified
    Evidently, the Data Source I am using is not correct, but I was provided no other information from the admin. This is the first time any of us have tried to connect to Oracle using ASP/VBScript, so the administrator isn't sure what I need to do ... any help would be so appreciated.

    Hello,
    I got mine to work by setting up an ODBC System DSN and connecting to it. I think this bypasses the Microsoft driver, which might be what's causing the problem.
    Set Db = Server.CreateObject("ADODB.Connection")
    Db.Open "DSN=TEST;User ID=userid;Password=password;"
    Good luck, I've found it requires a lot of persistence...
    Al
    Springfield, MO

  • Step by Step how we can connect SAP CRM to External system..

    Hi Experts,
    I want to know the informations of how we can connect sap CRM to External system, and what are the settings we have to do ,to enable XIF adapter..
    This is very imp requirement kindly give support.., how we can connect to other system..through XIF Adapter..??
    IS it possible to create ZBAPI in SAP CRM..?
    Thankz in Advance
    Regards
    J Sarathi

    Hi,
    - Xif adapters and service process the BDOC messages.
    - adapters for inbound and outbounfd processing.
    -it will forward the messages from  the inbound queues to the control component.
    -BDOC is a business document where the flow of data to and from the CRM system takes place.
    -Bdoc is a container that contain business data
    - it describes the hierarchial structure of the business data.
    -you can also create custom specific BDOC types,
    -BDOC's as a data container to process business objects as one unit and this avoid having to transport several individual tables.
    Bdoc types are found in BDOC repositry.
    Bdoc types have two part
    Header- consist of one single segment so-caooed control segment
    Body - consist of one or more data segment
    Idoc having three types of data:
    control record
    Data record
    status record
    hope it will useful.
    thanks
    Hemant ghiya

  • SBS and UCC

    Hi I have SBS 2011 and until recently I used remote.domain.com certificate for all (awesome). But new requirements came that I need to install Lync Server which exponentially increased number of needed SANs. So I bought UCC with 10 SANs and not I still have
    some place left to transfer remote.domain.com among the others. That way I would have only one certificate on ARR. 
    Can you please advice?
    CN for UCC is sip.domain.com, SANs - well 10 of them...
    This certificate was requested from Lync  Edge server (not SBS server)

    Hi,
    Sorry for my delay.
    UCC can be added via the SBS console wizard. However, extra domain names can't be added via the wizard.
    Please refer to following thread and article, then check if can help you.
    SBS
    2011 Standard and UCC certificates from GoDaddy
    SBS 2008 / 2011 adding
    an SSL certificate
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft
    does not guarantee the accuracy of this information.
    Hope this helps.
    Best regards,
    Justin Gu

  • Where/how to troubleshoot external gateway and internal connection brokers etc.??????

    We have gateway.domain.org as our external/internal gateway server.
    It goes from gateway.domain.org to rdbroker.domain.local, rdbroker is the DNS address for two connection broker servers.
    After this it should set up the connection and create a remote desktop to one of the RDS host servers in the RDS host farm.
    Sometimes this works, sometimes it doesn't -- for different user accounts and different computers.
    How to troubleshoot this??
    We know the firewall rules for DMZ etc. etc. are properly configured because everything IS observed to work, just not all the time consistently. We get errors about cannot contact the computer, cannot establish remote desktop connection...
    Thank you, Tom

    Hi Tom,
    Firstly, you need to recheck the DNS entry is well setup for your case. Are you using DNS RR for Load balancing the server or 3rd party load balancer? Have you setup the proper certificate for your case?
    Please check whether required ports is opened? We need to open TCP port 443 and UDP port 3391 and forward them to your RD Gateway server. Also need to specify the external FQDN of your RD Gateway server in deployment properties under RDS server manager. If
    you have RDWeb and RDG on the same server this would be the same FQDN that your users will use for RDWeb. Please see whether you have properly configured RD RAP and RD CAP policy. 
    You can go through beneath article for more details.
    Step by Step Windows 2012 R2 Remote Desktop Services – Part 3
    https://msfreaks.wordpress.com/2013/12/26/windows-2012-r2-remote-desktop-services-part-3/
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • SMTP Postfix refuses all connections both internal and external

    My server initially started bouncing all outgoing e-mail from our users saying that an invalid user name and password has been specified. Now it has progressed to bouncing all SMTP traffic both incoming and outgoing. I've got hours into trying to decode the mystery of why Postfix is doing this but still can't come up with an explanation. The server is an OD master running just AFP and Mail. Here is the output from postconf -n
    If anyone can provide me with some insight I would be extremely grateful!
    biff = no
    command_directory = /usr/sbin
    config_directory = /etc/postfix
    content_filter =
    daemon_directory = /usr/libexec/postfix
    debugpeerlevel = 2
    enableserveroptions = yes
    header_checks =
    html_directory = /usr/share/doc/postfix/html
    inet_interfaces = all
    mail_owner = _postfix
    mailboxsizelimit = 0
    mailbox_transport = dovecot
    mailq_path = /usr/bin/mailq
    manpage_directory = /usr/share/man
    mapsrbldomains =
    messagesizelimit = 10485760
    mydomain = mydomain.com
    mydomain_fallback = localhost
    mynetworks = 127.0.0.0/8
    newaliases_path = /usr/bin/newaliases
    queue_directory = /private/var/spool/postfix
    readme_directory = /usr/share/doc/postfix
    recipient_delimiter = +
    relayhost =
    sample_directory = /usr/share/doc/postfix/examples
    sendmail_path = /usr/sbin/sendmail
    setgid_group = _postdrop
    smtpdclientrestrictions = permit_mynetworks permitsaslauthenticated rejectrblclient zen.spamhaus.org permit
    smtpdenforcetls = no
    smtpdhelorequired = no
    smtpdhelorestrictions =
    smtpdpw_server_securityoptions = cram-md5,gssapi
    smtpdrecipientrestrictions = permitsaslauthenticated permit_mynetworks rejectunauthdestination permit
    smtpdsasl_authenable = yes
    smtpdtlsCAfile = /etc/certificates/server.mydomain.com.5E4E6414CE4D89A47A4D36A04661CAEAC9F0DE82. chain.pem
    smtpdtls_certfile = /etc/certificates/server.mydomain.com.5E4E6414CE4D89A47A4D36A04661CAEAC9F0DE82. cert.pem
    smtpdtls_excludeciphers = SSLv2, aNULL, ADH, eNULL
    smtpdtls_keyfile = /etc/certificates/server.mydomain.com.5E4E6414CE4D89A47A4D36A04661CAEAC9F0DE82. key.pem
    smtpdtlsloglevel = 0
    smtpduse_pwserver = yes
    smtpdusetls = yes
    unknownlocal_recipient_rejectcode = 550
    virtualaliasmaps =

    I'm also seeing entires like this in the SMTP log. I don't know if this is a misconfiguration of main.cf or something else that I haven't considered. Authentication for AFP works fine though.
    Feb 19 13:35:50 server postfix/smtpd[29788]: connect from unknown[10.0.55.116]
    Feb 19 13:35:51 server postfix/smtpd[29788]: lost connection after EHLO from unknown[10.0.55.116]
    Feb 19 13:35:51 server postfix/smtpd[29788]: disconnect from unknown[10.0.55.116]

Maybe you are looking for