Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Incoming email connection dropped unexpectedly with log

Dear all,

     Our customer has found a problem for sender email bounced back unexpectedly, he has found the error logged from blocker.

14 Oct 2009 08:02:06 (GMT +0800)
Protocol SMTP interface Data 2 (IP 192.168.1.202) on incoming connection (ICID 185273) from sender IP address: w.x.y.z. Reverse DNS host 124x34x77x73.ap124.ftth.ucom.ne.jp verified 1.
14 Oct 2009 08:02:06 (GMT +0800)
(ICID 185273) ACCEPT sender group UNKNOWNLIST match sbrs[-1.0:10.0] SBRS -0.1
14 Oct 2009 08:02:06 (GMT +0800)
Start message 56176 on incoming connection (ICID 185273).
14 Oct 2009 08:02:06 (GMT +0800)
Message 56176 enqueued on incoming connection (ICID 185273) from sanderling@senderdomain.com
14 Oct 2009 08:02:06 (GMT +0800)
Message 56176 on incoming connection (ICID 185273) added recipient (user1@targetdomain.com)
14 Oct 2009 08:02:06 (GMT +0800)
Message 56176 on incoming connection (ICID 185273) added recipient (user2@targetdomain.com).
14 Oct 2009 08:02:08 (GMT +0800)
Incoming connection (ICID 185273) lost.
14 Oct 2009 08:02:08 (GMT +0800)
Message 56176 aborted: Receiving aborted


Do anyone know why it will suddenly lost connection?

Regards,

Joe Tam

6 REPLIES
New Member

Re: Incoming email connection dropped unexpectedly with log


>>Incoming connection (ICID 185273) lost. <<

This refers to the sending MTA closing/losing the connection. This indicates a problem on the sender's side. Is the issue constant when receiving mail from 124x34x77x73.ap124.ftth.ucom.ne.jp  ? Or is it an intermittant issue?

New Member

Re: Incoming email connection dropped unexpectedly with log

You can enable the injection logs using Log Subscription. Than go to the command line and type tail ... select the number for the injection logs. This are real time logs which will give you the information if the sender of the message really quite the connection.

KR,

Edgar

New Member

Re: Incoming email connection dropped unexpectedly with log

I am receiving the same error message as above. I appear to only be getting the message when the sender is sending me an attachment. Any ideas on how to correct this?

Thanks,

Nic

New Member

Re: Incoming email connection dropped unexpectedly with log

If the Blocker is the one terminating the connection there should be a log as to why it decided to do so. Hopefully finding the transaction in your logs regarding the connection that's being dropped would give you a good starting point. If it is attachment related, I would look into the antivirus logs to see if it is being rejected by the Sophos scan due to potential virus payload. Otherwise, if the sender is receiving a bounce message, the contents of the bounce may give us some insight as to what may be going on.

New Member

Re: Incoming email connection dropped unexpectedly with log

Is there a place in the blocker that limits the size of attachments? The bounceback said something about the message being to big or the receivers mailbox being full. Both of these are set correctly on the server. Any ideas?

Thanks,

Nic

New Member

Re: Incoming email connection dropped unexpectedly with log

You can limit the size of incoming mails in the Mail Flow Policy. The MFP is attached to a Sender Group (SG) in the Host Access Table (HAT). Therefore, you have to find out in which SG the sender will have a match (mail_logs will give you a helping hand doing this). The SGs are first match out: the match is based on the SBRS or the Sender address.

Cheers,

Edgar

6237
Views
0
Helpful
6
Replies
CreatePlease to create content