I have found that inbound mail to distributions groups (Ex07) are not being delivered. Running a trace, I am seeing they are failing on LDAP match. I tracked it down to the qroup query not working. We are using the default query. Running a test, it fails. I think that is the problem. I can mail the group internally just fine.
Anyone have a good query string that will check for distribution groups? Below is the query being used. Thanks for the help.
To make sure you have the full DN of the group membership, I would recommend using an LDAP tool like ldapbrowser.com. It is free and very easy to use. It will display the entire structure of your LDAP server and show you all the info you need without compromising security.
Ding! Won't be necessary, got it working. Your comments got me looking in the correct location, and I found the problem, thank you. Ironically enough the support engineer emailed me the fix too while I was making the changes.
Further examination of the ldap settings themselves and not the query, showed the problem. I have all of our users in ou=XusersX, dc=domain, dc=com
All of my mail distribution lists (to make it easy for the help desk) are in ou=distribution lists, dc=domain, dc=com
My base DN was set to the user OU, so whenever i tested against a distro group, the base dn was at a parallel level as the distro ou, so it wasn't even searching here, and hence failed.
Thanks again guys for pushing the brain in the right direction!
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...