Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Exchange 5.5 issues .. I'm stumped ...

Status
Not open for further replies.

itchyfish

MIS
Jun 1, 2004
19
US
Here's where I stand at as of tonight. I've got Exchange 5.5 SP4 for a front end and a back end. I have my SMTP Connector on a seperate NT4 Svr.

Whenever I enable the SMTP connector, the Queue fills with 1000's of email. Now with that said, I've run the Perfmon on the backend Exchange server when the SMTP connector is on and the MTS-OUT runs nonstop. The CPU on the backend server is running at 97% on the IMC service.

If I disable the IMC service, it takes the server a few minutes, but the service does stop and the server returns to normal.

My problem is I don't know where the problem lays - is it with the server with the SMTP connector or is it the backend server. All 3 servers have virus scanning software in which it has detected a few viruses and has removed them.

I found a few articles that explain to run a few utilities on cleaning the IMCDATA Out and In folders to remove any possible emails with viruses with no joy.

I'm stumped and have no idea where I need to go from here. Any help is going to be greatful!

Thank you,

Mike
 
Perhaps you simply have 1000s of messages wiating to get to the internet. It might help if you simply let the IMC run for a day or two to let them clear out. If you don't run the IMC except for a few hours a day, you'll be likely to get a hefty backup of outgoing messages.

Of course, you don't say how many users you have so it's hard to be of too much help.
 
Thanks for the reply.

The IMC runs 24x7x365 ... we only have 45 users in exchange.

It's really a problem .. I know we don't generate 1000 msgs a week, let alone every hour.

I hope that helps out a little better.

Regards,

Mike
 
Its likely a reverse NDR attack. Search this forum for <> or RNDR. There are several threads on the problem.

Cheers.
 
It looks like you may have an open relay. I would suggest taking the server off linie and deleting the messages from the queue. Once all gone, put the server back online and test for open relay at
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top