Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Email Security Quick-links: ESA Product Support | SMA Product Support | Email Submission and Tracking Portal | Cisco SecurityHub
Current General Deployment (GD) Releases:
ESA: 11.0.0-264 WSA: 10.5.1-296 SMA: 11.0.0-115 Email Plug-in (Reporting): 1.0.1-048 Email Plug-in (Encryption): 1.0.0-036

New Member

Connection Timeout/Lost on C350:

Hello,

We've got a C350 installed at an ISP customer and recently, they've started to experience some major mail receiving problems with a specific domain(one of their major partners).
Connections are lost and some even get the 501 5.5.4 Invalid Address Error.

The Partner is using MS Exchange and using a WiMax connection to the ISP.
Exchange is sending mail directly and the mail is going through a PIX for Wimax customers and then going through ISP PIX before entering the C350.
SMTP Fixup turned off on both PIX.

See below, most of the time, the connection is initiated but after 20-50 minutes, the connection is lost. I've configured the timeout to 1 hour on IronPort:


22 Jun 2008 12:08:32 (GMT +0400) Message 1644287 on incoming connection (ICID 10308995) added recipient (user@domain.com)
22 Jun 2008 12:50:59 (GMT +0400) Incoming connection (ICID 10308995) lost.
22 Jun 2008 12:50:59 (GMT +0400) Message 1644287 aborted: Receiving aborted

--------------------
Second Issue:
501 5.5.4 Invalid Address, when mails are sent from the partner to ISP client.


Can you please help me on this?
Is there a timeout settings on the PIX which could be causing this problem?
Note that the partner can send mails to anywhere else and no problem. Same for the ISP.

Thanks,
Vinesh

4 REPLIES
New Member

Re: Connection Timeout/Lost on C350:

Hi all,

I had a similar problem with you.

My user is complaining that outgoing mail had rejected by ironport suddenly.

How can i to get the ironport best practices in the production environment especially for sending huge of outbound email?

Where is the alert and logs to prove the ironport had reject these connection?

How can I set these alert to monitor like the workqueue is full or the concurrent TCP connection is overloaded?

Thanks for the help.

New Member

Re: Connection Timeout/Lost on C350:

Is (are) the PIX(es) with the "fixup" feature enabled for SMTP ?

I saw once that this kind of configuration made this strange behaviour to happen and it was not IronPort's fault at all, IronPort was not guilty.

New Member

Re: Connection Timeout/Lost on C350:

Hi,

I told the client to disable smtp fixup on the PIX. So, now both are disabled, but problem is still here.
What is amazing is that it happens only intermittently when sending some large files. All the test mails we sent, was received without problem.
I was perhaps thinking that there might be a DPI or smtp timeout setting on the PIX. Any ideas?

thanks,
Vinesh

New Member

Re: Connection Timeout/Lost on C350:

Hi there, best thing you can do is to create a Injectiond Debug Log, and specify the IP address of the remote sender, once you commit your changes tail this log in the CLI and you will see the full SMTP conversation. Alternatively if you are running 6.1 there is a new log type called SMTP Conversation which will do the same thing.
These logs will help you diagnose the issue a little better :lol:

1115
Views
0
Helpful
4
Replies