Exchange Server 2010 Mailflow between Internet Facing-Site and No Internet Facing-Site

Hi all,
My environment there are two sites, Internet Facing-Site and No Internet Facing-Site.
The mail flow between them, it isn't working. The messages stuck in the queue.
Default Receive Connector No internet facing-site is configured, bellow:
Defaul....
- Transport layer....
-Basic Authentication...
- Exchange Server Authentication.
- Integrated windows....
Configuration the Internet Facing-Site, bellow:
From intenet
- Transport layer....
-Basic Authentication...
- Integrated windows....
And i configured a new receive connector on the Internet Facing-Site, follow bellow:
Sites
- Transport layer....
-Basic Authentication...
- Exchange Server Authentication.
- Integrated windows....
But, the messages yet stay stuck in the queue.
Queue error:
451 4.4.0 Primary target IP address responded with: “421 4.2.1 Unable to connect.” Attempted failover to alternate host, but that did not succeed. Either there are no alternate hosts, or delivery failed to all alternate hosts.
I'm needing help, pls.

Please check SMTP traffic filtering/scanning enabled on the router/firewall. You can telnet even if the SMTP
traffic filtering/scanning enabled on the router/firewall. But emails will not pass through if the configuration is incorrect.
May be speed between sites causing this issue (not sure). Anyway please try changing the Tarpitinterval as a test.
To see the current setting "Get-ReceiveConnector | Select name,tarpitinterval "To set new value "Set-ReceiveConnector “<Connector-Name>”
–TarPitInterval:00:00:010"
Try restarting "MSexchange-Transport-sevice" on both servers as well
Can you send email one-way or
both ways not working? 
MAS

Similar Messages

  • Exchange Server 2010 mailflow reporting using SCOM 2007

    Hi,
    We are using SCOM 2007R2 in our Organization and we are Monitoring Exchange server 2010.
    We are in need of reports for Mailflow statistics (send and receive)from Exchange server 2010 using SCOM 2007R2.
    Eg: Microsoft Exchange 2010 Server Reports Transport Platform Hourly server Statistics.
    By default reports available in SCOM for Exchange server will not fulfill our requirement.
    Earlier for Exchange server 2007 we are able to fetch the desired reports which is available by default.
    Eg:  Exchange 2007 SMTP Message Received
           Exchange 2007 SMTP Message Sent
    Is there any way to fetch the reports for Exchange server 2010 same as Exchange 2007 reports.
    Thanks

    Hi SonarPal,
    Please look at this post, hope it helps:
    https://social.technet.microsoft.com/Forums/en-US/ffdb8883-226f-410f-abde-bd75c4c88c4a/exchange-transport-reports-no-data?forum=operationsmanagerreporting
    Natalya
    ### If my post helped you, please take a moment to Vote as Helpful and\or Mark as an Answer

  • Installing second Exchange server 2010 with all roles (CAS, HT and MB) in the same domain?!

    Dear all,
    first of all thanks for reading this topic :-)
    In our enviroment, we have a Exchange 2010 server (Version: 14.01.0438.000), whitch is installed with all server roles (CAS, HT and MB) on one server(OS is Windows Server 2008 R2 Enterprise). This exchange server sends all external mails to a smarthost (Redddox).
    We are using Outlook Anywhere, Active Sync and OWA.
    Now, we need to migrate this Exchange server to another one, because we think, that the server´s OS is corrupt and also, there are wrong licenses installed. The "new" server will have the same OS Version and Exchange Version (2010).
    Currently I´m a little afraid, to install a new one - because I think when I will install the CAS and HT role, something will happen in my productive enviroment (Autodiscover, SMTP Connectors, Cerficates a.s.o.).
    To install the mailbox role, I think this will not affect anything.
    Can you help me a little bit in what to take care of? Do I need to preconfigure something, before I will install the second exchange? What about the version / service pack of Exchange to install? Must it be the same as installed on the first one?
    Any help would be appreciated!
    Jennie

    Hi Jennie,
    Below are the steps if you are not planning to upgrade.
    1) Install new Exchange2010-SP3 Server all roles Please check
    this
    2) Install the certificate in the new server by requesting a duplicate from the 3rdparty CA. Or export from the existing Exchange 2010 and import to the new one. Please check
    this
    3) Set your autodoscover, OAB, ECP, OWA URLs same as the current Exchange. Below artciles will help you to do that.
    For OAB, Autodiscover, EWS please check steps 5,6,7in this
    For setting OWA and ECP URLs please check
    this.
    4) Move few mailboxes as a test and check. If no errors move the rest.
    5) Move your OAB generation server to the new server. Please check
    this
    6) Move you public folder contents to the new server you have. Please check
    this
    7) Configure your firerwall to receive emails on the new server and other services like EWS, OWA, ActiveSync.
    8)
    Add the new server as the source server and in the current send connector and remove the old server from the send connector.
    Shutdown the server for a couple of days and monitor. So you will know if you missed something.
    Uninstall Exchange2010 from the add remove programs.
    Thanks, MAS
    Please mark as helpful if you find my comment helpful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

  • Exchange Server 2010 SP3 Installation with UM Language Pack Error

    Hi All,
    Kindly help me in this issue, When I Install Exchange Server 2010 SP3, I faced an error in UM role setup as the below,
    and when i searched on it i found solution like "Download the UM language packs and tried to install directly" so i downloaded "UMLanguagePack.en-US" from the below URL:
    http://www.microsoft.com/en-eg/download/details.aspx?id=36769
    and when i tried to install it, i faced the below error:
    also i searched on this error and i found solution in registry as the below:
    Try remove registry key for the above error :
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\<Your Version >\UnifiedMessagingRole\LanguagePacks"
    and after i did it, i found first error be solved and the second error still the same as the below:
    Error:
    A Setup failure previously occurred while installing the UnifiedMessaging role. Either run Setup again for just
    this role, or remove the role using Control Panel.
    Is there a solution on this issue please i wanna solve it As soon as possible?
    Thanks in advance,

    I solved the below error by editing in registry:
    Error:
    A Setup failure previously occurred while installing the UnifiedMessaging role. Either run Setup again for just this role, or remove the role using Control Panel.
    Solution:
    Open regedit (Start -> run), navigate to the following key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14
    Under each role, UnifiedMessagingRole, have a look for an action and watermark entry, Delete these 2 keys, and retry. it solve this error, and You can now run the installation again of your "UMLanguagePack.en-US". and its done and installed now.
    After "UMLanguagePack.en-US" Installation, i tried to continue installation of Exchange Server 2010 SP3, but I faced the same first error in UM role setup as the below,
    What can i Do? please help urgently.

  • Microsoft Exchange Server 2010 SP3 update to Update Rollup 8-v2 for Exchange Server 2010 SP3

    i have Microsoft Exchange Server 2010 SP3 and i would like to update to Update Rollup 8-v2 for Exchange Server 2010 SP3. 
    what is the best way to do so?
    my current env:
    Name                : xxxxxxxx
    Edition             : Standard
    AdminDisplayVersion : Version 14.3 (Build 123.4)
    ServerRole          : Mailbox, HubTransport
    Site                : domain/Configuration/Sites/xxx
    Name                : yyyyyyyy
    Edition             : Standard
    AdminDisplayVersion : Version 14.3 (Build 123.4)
    ServerRole          : Mailbox, ClientAccess, HubTransport
    Site                : domain/Configuration/Sites/yyy
    Name                : cccccccc
    Edition             : Standard
    AdminDisplayVersion : Version 14.3 (Build 123.4)
    ServerRole          : Mailbox, ClientAccess, HubTransport
    Site                : domain/Configuration/Sites/ccc
    Name                : dddddddd
    Edition             : Standard
    AdminDisplayVersion : Version 14.3 (Build 123.4)
    ServerRole          : ClientAccess
    Site                : domain/Configuration/Sites/ddd
    Name                : iiiiiiii
    Edition             : Standard
    AdminDisplayVersion : Version 14.3 (Build 123.4)
    ServerRole          : Mailbox, ClientAccess, HubTransport
    Site                : domain/Configuration/Sites/iii
    thanks
    Mayson

    Consider referring to the articles below and that explains it all.
    Install the Latest Update Rollup for Exchange 2010 - https://technet.microsoft.com/en-us/library/ff637981.aspx
    Applying Service Pack and Rollup Updates on Exchange Server 2010 (Part 1) - http://www.msexchange.org/articles-tutorials/exchange-server-2010/management-administration/applying-service-pack-and-rollup-updates-exchange-server-2010-part1.html
    Pavan Maganti ~ ( Exchange | 2003/2007/2010/E15(2013)) ~~ Please remember to click “Vote As Helpful&quot; if it really helps and &quot;Mark as Answer” if it answers your question, “Unmark as Answer” if a marked post does not actually answer your
    question. ~~ This Information is provided is &quot;AS IS&quot; and confers NO Rights!!

  • Exchange Server 2010: Incoming mail not delivered

    I have an Exchange Server 2010 Standard with all recent patches and updates. 
    -It has been in service for 3 years without any issues. 
    -There is plenty of hard drive space for the logs and the data (over 100GB in each)
    -The current size of the mail database is 150GB
    -There is no registry entry in place limiting the size of the database ([url="http://technet.microsoft.com/en-us/library/bb232092.aspx"]Database Size Limit in GB as outlined here[/url]
    Starting a few days ago, incoming mail is reaching the server but not being delivered to user mailboxes. Internal mail works fine when this happens. Looking at the Queue Viewer doesn't show anything abnormal. The Submission Queue shows nothing.  
    It is only after I reboot the Exchange Server that the Submission queue will show all the messages waiting to be delivered and they will all be delivered successfully after the reboot. The event logs do not show any error messages.
    The server will continue to run fine for a few hours and then the problem starts all over again.
    What could be causing this?

    Any 3rd party antivirus/anti-spam software installed on the server? If so, disable and test.
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Step by step upgrading exchange server 2010 standard to enterprise edition

    step by step upgrading process exchange server 2010 standard to enterprise edition

    Exchange standard and Enterprise edition have the same ISO image. it's just the license that you have to enter and corresponding features will be enabled. If you are planning to upgrade existing Exchange 2010 Standard to Exchange 2010 Enterprise then simply
    apply the licenses of Enterprise edition. But if you want to upgrade to Exchange 2013 enterprise then install exchange 2013 in your environment and apply Exchange 2013 Enterprise edition licenses. Hope this answer your query. Thanks.
    Kindly mark this as answer if found helpful. Thanks.
    Regards, Riaz Javed Butt | Consultant Microsoft Professional Services MCITP, MCITP (Exchange), MCSE: Messaging, MCITP Office 365 | msexchgeek.wordpress.com

  • Exchange server 2010 redundancy using static IPs in different sites

    Dear All;
    We are facing a problem in Exchange server 2010 which is that we need to provide redundancy for two different sites which contain the same exchange databases using DAG but the issue is that if the main exchange server fails, users from the internet will
    not be able to access the server because the main static IP is in the main site ...
    ========================================
    My question is how to provide redundancy using two Global IPs in two different sites, and is there any consequences of doing such a setup?
    ========================================

    Hi,
    From your description, I would like to clarify the following things:
    1. It is recommended to configure the IP Configuration for both the MAPI and Replication NIC on DAG nodes.
    2. A site failure is managed differently from the types of failures that can cause a server or database failover. A site failure is considered to be a disaster recovery event, recovery should be manually performed and completed for the client service to
    be restored and for the outage to end.
    For more information, here is an article for your reference.
    Switchovers and Failovers
    http://technet.microsoft.com/en-us/library/dd298067(v=exchg.141).aspx
    Besides, what do you mean by "global IPs"?
    Hope it helps.
    Best regards,
    Amy
    Amy Wang
    TechNet Community Support

  • Exchange Server 2010 SP3 test environment - email flow to/from internet

    Today I set up test environment for Exchange Server 2010 SP3 - domain controller running Windows Server 2008 R2 SP1, Exchange Server 2010 SP3 on Windows Server 2008 R2 SP1 and client computer running Windows 7 Pro SP1 x64 with Outlook Pro 2010 x64. These
    machines are VMs on vSphere 5.0 cluster made of 4 esxi 5.0 hosts.
    I have three years of experience in working with Exchange Server 2010 in my production environment but until recently I have not had enough resources to build a test environment. Does "testing" Exchange Server 2010 infrastructure have
    a real life purpose considering the fact that only internal email flow is possible since authoritative SMTP accepted domain is not hosted anywhere thus not visible to outside world. This limited email flow combined with absence of possibility to test
    ActiveSync, Outlook Anywhere, OWA from WAN, . . . really hurt and make Exchange Server rare technology that can not be tested completely before introducing something new into the production. Services that are not possible to test from the outside world are
    useless and whole point of Exchange-like technologies is availability from anywhere and from whatever device.

    I set up Internet Send Connector (by default this type of send connector uses DNS MX records to route email automatically). Having sent an email to my gmail account I did not receive it and in transport logs I saw that mx record was found successfully
    but there is the following line:
    2014-08-05T20:39:51.942Z,Internet Connector,08D17F000FE36010,1,,2a00:1450:4013:c01::1b:25,*,,"Failed to connect. Error Code: 10051, Error Message: A socket operation was attempted to an unreachable network 2a00:1450:4013:c01::1b:25"
    I tried also to send an email to my production email address (we have Symantec Messaging Gateway which is used as a smart host (antispam,antimalware,content filter appliance)) but then error is:
    2014-08-05T20:50:08.395Z,Internet Connector,08D17F000FE36019,1,,91.238.7.10:25,*,,"Failed to connect. Error Code: 10061, Error Message: No connection could be made because the target machine actively refused it 91.238.7.10:25"
    Telnet from test exchange to 91.238.7.10 on port 25 also is not working.

  • DAG in exchange server 2010 across different sites

    hello ;
    I want to know the best way to implement DAG for exchange server  2010 across 2 sites in the same domain ,
    I have 2 exchanger server in one site in DAG ,with 300 gb database size  
    but I want to implement exchange server 2010 in a new site within the same domain  and this will be my 3rd  exchange server and will be a member on my existing DAG in the head office  
    the new site is linked to my head office using ipvpn connection which is 6 mb , and ADC is there in the new site, 
    what is the best way to implement the new exchange server in the new site to join the existing DAG .
    is there is any problem related to DAG in this scenario ? 
    what is the best way to implement this scenario ?
    Thanks   

    Hi,
    For each AD site, it is recommended to have at least there Exchange roles: CAS, HUB, and MBX roles.
    Do you plan to have active users in this new site?
    If there are active users in this new site, you can deploy a Three-Member DAG in two AD sites. However, it is recommended to deploy two DAGs in two AD sites and you should have at least two DAG members each AD site. This scenario, two witness servers in
    separate site is necessary.
    If the new site is only for DR purpose, you can install this new Exchange server and add it to DAG. After that, add database copy to this new server.
    Besides that, here are two articles which may help you for your reference.
    Database Availability Group Design Examples
    http://technet.microsoft.com/en-us/library/dd979781(v=exchg.141).aspx
    Understanding Database Availability Groups
    http://technet.microsoft.com/en-us/library/dd979799(v=exchg.141).aspx
    Hope this helps.
    Best regards,
    Belinda
    Belinda Ma
    TechNet Community Support

  • Exchange server 2010 unable to send internet mails to some domains but receives mail

    Hi all, I have exchange server 2010 deployed and can receive mail with no issues but cant send mails to some external domains. I can send mails to gmail some others. Yahoo! is among the domains that rejects mails originating from my exchange server. Is
    there anyone to assist please?

    You can start here.
    http://www.dummies.com/how-to/content/how-to-get-removed-from-an-email-blacklist.html
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • Allocating and delegating permissions in Exchange Server 2010 between two AD security group.

    People,
    Can anyone please assist me in where and how to assign the following two AD security group in Exchange Server 2010?
    IT Admin group (Full access and permission for all AD and Exchange related).
    IT Helpdesk group (can only create mailbox and modify the mailbox properties including AD distribution group and contacts).
    Because in Exchange Server 2007, everything can be managed easily through the AD security group that is created during the installation such as
    Exchange Organization Administrators group for full access for IT Admin team and Exchange Recipient Administrators group for managing the mailbox user for Help Desk team.
    /* Server Support Specialist */

    Hi,
    Based on my knowledge, Exchange 2010 has an Organization Management group instead of the Exchange Organization Administrators group. Use the Recipient Management group instead of the Exchange Recipient Administrators group. In your case, you can add the
    IT Admin group to the Organization Management group, add the IT Helpdesk group to the Recipient Management group.
    Hope this can be helpful to you.
    Best regards,  
    Amy Wang
    TechNet Community Support
    Thanks, Amy,
    But for some reason I cannot see those built in AD security group in my ADUC?
    So should I recreate it manually by right clicking on the AD user and Console ?
    /* Server Support Specialist */

  • Mail Delivery betweek Exchange Server 2013 co-existance with Exchange server 2010

    Hello Guys
    I have a mailflow issue, hoping someone can help with detail description, below is the setup
    Exchange server 2010 SP3 with all roles in one server
    Exchange server 2013 SP1 with CU6 with all roles in one server - this server is in a different subnet to the 2010 server. I am able to see exchange 2010 databases and mailboxes from Exchange 2013. For testing purposes, I have moved 3 mailbox from 2010
    to 2013. These 3 mailbox, is able to send and receive email from Internet but to each other via OWA or Outlook. These 3 mailbox also not able to send to receive email from any mailbox that is still in 2010 server via OWA or Outlook. I am not planning the whole
    server cutover in a go and planning to do state by stage mailbox migration so I need mailflow working properly. When I send an email from one of the migrated mailbox that is in 2013 server, I can see that the email leaves the mailbox outbox and sits in the
    queue ..
    Can someone please provide detailed solution what needs to be configured?
    MCITP, MCSA, MCSE,VCP - Consultant, Solution Design, Implementation

    Hi,
    1.please check the mailbox send and receive quota for exchange 2013 migrated mailbox.
    2.Please check the email attributes of the exchange 2013 migrated mailbox because it seems to be a problem with that particular mailbox.
    3.Then do the message tracking and that would be the only way to find the where the send messages has gone.
    4.Please check and confirm you have an enough space on the disk where exchange queue database is residing.
    I think I need to create a receive connector in the 2013 to receive from 2010 ?
    No need ,by design  exchange 2013 cas server default frontend receive connector will be having an
    entire ipv4 and ipv6 segment and anonymous connection is checked by default.
    I think I also need to create a send and receive connector for 2013 users to each other?
    No need , an intra organisation send connector and the default receive connectors in exchange will be used
    for internal mail flow between the exchange 2013 users.
    Please reply me if you have any queries .
    Regards
    S.Nithyanandham
    Thanks S.Nithyanandham

  • Windows Server 2008 R2 Standard "Certificate Authority Service" / Exchange Server 2010 EMC not starting and no AD connectivity for authentication.

    Hello,
    I am a new IT Manager at this company and need assistance big time. Their environment looks as follows:
    Server 1. Domain Controller Server (Windows Server 2008 R2 Standard) running active directory.
    Server 2. Email Server (Windows Server 2008 R2 Standard) running Exchange Server 2010 .
    * Note. No back ups to work with aside from whats mentioned below.
    DC had a virus infection causing a lot of issues on the shared network drives 2 days ago locking up all the files with a crypto ransom virus. Running Avast suppressed the infection. Had to recover the file shares which luckily had a back up. 
    The issue is that the Exchange Server 2 post this lost connectivity with the AD Server 1. Exchange Server 2 when launching EMC could not launch the console stating the following:
    "No Exchange servers are available in any Active Directory sites. You can’t connect to remote
    Powershell on a computer that only has the Management Tools role installed."
    Shortly after I found that it is possible the EMC launcher was corrupt and needed to be reinstalled following another blog post. I deleted the exchange management console.msc  per instructions only to discover I couldnt relaunch it because there was
    no way how. So I copied another msc file that happened to be on the DC Server 1  back to Exchange Server 2 and got it to launch again. 
    Another post said that it might be an issue with the Domain Account for the Computer, so to delete it in the AD Server 1 only to find that rejoining it from Exchange Server 2 using Computer>Properties> Chage Settings > Change is greyed out because
    it is using the Certificate Authority Service.
    I tried manually re-adding the computer in AD and modeling permissions after another server in group settings but no go. After this I was unable to login to the Exchange Server 2 with domain accounts but only local admin, receiving the following Alert:
    "The Trust Relationship between this workstation and primary domain failed."
    I tried running the Power Shell tools on Exchange Server 2 to rejoing and to reset passwords for domain accounts as noted in some other blogs but no luck as the Server 2 could not make the connection with Server1 or other errors it kept spitting out.
    I also during the investigation found the DNS settings were all altered on both the Server 1 and Server 2 which I luckily was able to change back to original because of inventorying it in the beginning when I started. 
    I need help figuring out if I need to rejoin the Exchange Server 2 manually by disabling the Certificate Authority Service (or removing the CA as listed here:
    https://social.technet.microsoft.com/Forums/exchange/en-US/fb23deab-0a12-410d-946c-517d5aea7fae/windows-server-2008-r2-with-certificate-authority-service-to-rejoin-domain?forum=winserversecurity
    and getting exchange server to launch again. (Mind you I am relatively fresh to server managing) Please help E-Mail has been down for a whole day now!
    Marty

    I recommend that you open a ticket with Microsoft Support before you break things more.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • All sub-folders in Mac Mail cannot synchronize with Exchange Server 2010

    Hi all,
    All sub-folders under Inbox in Mac Mail cannot be synchronized with Exchange Server 2010. There are 2GB messages size in Inbox folder and 500MB messages size under Inbox's sub-folders. All messages can be sent out and received and it can work in Outlook 2007 and Outlook 2010 normally. However, all messages in sub-folders cannot be synchronized (empty sub-folders).
    Does this problem relate to message synchronization order of Mac Mail with Exchange Server? Do all sub-folders messages be synchronized after synchronization complete of Inbox? The synchronization of sub-folders will not happen if the synchronization of Inbox does not complete, doesn't it?
    All messages synchronization is over internet. Can anybody help?
    Thanks a lot
    DT1640759

    Hi,
    1.please check the mailbox send and receive quota for exchange 2013 migrated mailbox.
    2.Please check the email attributes of the exchange 2013 migrated mailbox because it seems to be a problem with that particular mailbox.
    3.Then do the message tracking and that would be the only way to find the where the send messages has gone.
    4.Please check and confirm you have an enough space on the disk where exchange queue database is residing.
    I think I need to create a receive connector in the 2013 to receive from 2010 ?
    No need ,by design  exchange 2013 cas server default frontend receive connector will be having an
    entire ipv4 and ipv6 segment and anonymous connection is checked by default.
    I think I also need to create a send and receive connector for 2013 users to each other?
    No need , an intra organisation send connector and the default receive connectors in exchange will be used
    for internal mail flow between the exchange 2013 users.
    Please reply me if you have any queries .
    Regards
    S.Nithyanandham
    Thanks S.Nithyanandham

Maybe you are looking for

  • I just installed a second, larger hard drive. Can I copy all of the files?

    I have a G5 Tower with an 80GB Seagate hard drive. I just installed a 160GB Seagate in the second bay. It seems to be connected. I partitioned it. Can I now simply copy everything that was on the old hard drive onto the new one? Do I then tell the co

  • Connection to server times out

    Hi, I know I've seen somewhere that you can set how long before your connection to your remote server times out in DW. After a few minutes of editing files, and then when I go to upload them to my host, It takes forever just to make a connection. I u

  • Need for NPS server certificate with PEAP-MS-CHAPv2

    Hi, I have a question about a small setup I'm currently testing. In a Wireless access with 802.1X authentication based on PEAP/MS-CHAPv2, and a NPS server (MS server 2012R2), I've noted reading technet documentation that the NPS server or other RADIU

  • Bug in latest drivers

    Some time ago (somewhere in 2008 I thought it was a good idea to update my drivers to the latest update (was using the drivers from the cd before that, because I don't get all the software otherwise) After I done the update, it completelly screwed so

  • Doubt on Order Quantity

    HI all, Currently i am using the datasource 2LIS_11_VAITM. I have activated the datasource. And i run this datasource in RSA3.I have compared the data with the Table level data. In this datasource, there is a field called Order Quantity (KWMENG). I h