Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

Aborted: Receiving aborted from Domain @xx.com after 9 min lost , Please help

16 Jul 2013 15:23:35 (GMT +07:00) Protocol SMTP interface Data 1  (IP 10.201.31.241) on incoming connection (ICID 1735665) from sender IP 209.85.192.170. Reverse DNS  host mail-pd0-f170.google.com verified yes.
16 Jul 2013 15:23:35 (GMT +07:00) (ICID 1735665) ACCEPT sender group UNKNOWNLIST match sbrs[none] SBRS unable to retrieve
16 Jul 2013 15:23:38 (GMT +07:00) Start message 2534709 on incoming connection (ICID 1735665).
16 Jul 2013 15:23:38 (GMT +07:00) Message 2534709 enqueued on incoming connection (ICID 1735665) from

xx@.co.th

16 Jul 2013 15:23:38 (GMT +07:00) Message 2534709 on incoming connection (ICID 1735665) added recipient (xx@.co.th).
16 Jul 2013 15:32:15 (GMT +07:00) Incoming connection (ICID 1735665) lost.
16 Jul 2013 15:32:15 (GMT +07:00)

Message 2534709 aborted: Receiving aborted

after 9 min lost , Please help

2 REPLIES
Cisco Employee

Aborted: Receiving aborted from Domain @xx.com after 9 min lost

Hello Network Security Team,

What you're seeing here can occur from different variables.

Possibly transmission loss during the data transfer on the connection


Firewalls changing packets

Some packets dropped by Firewall

ESMTP inspection enabled on the firewall.

It will be mainly network/firewall related.

You will need to start up an injection debug log on the appliance GUI > System Admin > Log Subscription
Add a new log > log type > injection Debug for the injecting IP of 209.85.192.170
Replicate this issue and it will log down what is going on with the connection in detail, after which you can open a TAC case and provide us this log to investigate.

Additionally, you can run a packet capture and replicate this issue, if you have your network engineers review the capture you will most likely find the culprit causing it.

GUI > Help and Support > Packet Capture > Start on port 25 and replicate this, stop the capture and review.

New Member

Aborted: Receiving aborted from Domain @xx.com after 9 min lost

Hello,

What is the value for 'Timeout for Unsuccessful Inbound Connections' on your appliance? Is it set to 9 minutes?

You can find this parameter in the Global Settings Pane ine the Network>Listeners page.

Does this connection attempt regularly repeat in your log and is always interrupted at 9 minutes?

From my experience, the distant MTA does not manage to send the message before the Timeout (poor bandwith on its side, poor bandwith on your side for instance) and your appliance interrupts the transmission.

Something to consider before going in debugging mode.

Regards,

5563
Views
0
Helpful
2
Replies
CreatePlease login to create content