Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

NDRs after ISP and Default Gateway Change

Status
Not open for further replies.

kenclaimy

MIS
Jan 22, 2004
12
GB
Hi,

I am currently implementing a new MPLS based WAN, with an internet connection at head office. Hopefully the diagram below helps explain topology.


Site2
\{mpls}- Site1(HO) - |fw| - {internet}
/
Site3

there are MPLS routers at each site, and each client PC or server has this as the default gateway. If IP address cannot be reached (i.e. is an external address) packets are routed to the firewal at HO.

Client PCs work fine (can access other clients at each site and internet)

Exchange server at HO works fine, can telnet on 25, webmail, send out, recieve in.

Exchange server at site 2 responds to telnet 25, webmail works, email is recieved BUT when sending comes back with the following:

test@test.co.uk on 23/05/2006 20:43
You do not have permission to send to this recipient. For assistance, contact your system administrator.
<site2exchangeserver.mydomain.local #5.7.1 smtp;550 5.7.1 <test@test.co.uk>... Relaying denied. IP name possibly forged [xxx.xxx.xxx.xx]>

I think the problem is with the SMTP virtual server at site2, it did have dns entries and smart host for our old ISP but I removed these. I also removed current ISPs DNS servers from DNS forwarding.

Is there anywhere apart from DNS or SMTP virtual server I could check for references to the old default gateway or old ISP DNS servers?

Problem can't be with new ISP, as mail server at site 1 works fine

Problem can't be with firewall as mail comes in, telnet on 25 works, webmail works, nslookup works, web browsing from server works

It looks like the problem is specific to outgoing SMTP mail

Any help greatly appreciated

TIA
 
OK,

found another reference to the smart host in the properties for the external mail connector

So, before I go through all the tests again, can anyone say whether or not the NDR I recieved is indicative of the server attempting to use a smarthost?

The ISP smart host only accepts connections from clients on its network

Cheers
 
...I also removed current ISPs DNS servers from DNS forwarding...."
Why would you remove the current?

MPLS = diff. subnets
it sound like realy deal...
-check your relay and see if it allows for the 'remote subnets' to do so.
-check your server IPs and make sure that ther is no ref. to old subnets (on any server NIC even the one that is disabled)
-You can always add your server into allowed relay servers.
are the other sites on the same domain?
..far from being an expert but perhaps a few things to look at for now...
All the best!

:--------------------------------------:
fugitive.gif

[URL unfurl="true"]http://mostarnet.com[/url]

All around in my home town,
They tryin' to track me down...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top