Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Mail Security: SMTP, POP3, Antispam and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-17-2009, 09:52 PM
Member
 
Join Date: May 2008
Posts: 30
Default [7.403] NDR for relayed outbound email

Hi,

We are currently running V7.403 and would like to use the outbound relaying function of our astaro unit. In our testing we have found that the exim email system does not return NDR's to our users if there was any problem delivering the emails. This is a big problem since our users would not know if there where any problems with delivery.

If we direct our exchange 2003 server to deliver emails directly instead of sending them through the astaro unit we get the NDR's. Is there anyway to change this configuration? Below the user never received an NDR.

***Clip from log***
2009:06:16-19:23:50 xyz smtpd[2467]: SCANNER[2467]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="192.168.***.***" from="user@xyz.org" to="user@xyz.com" subject="Test" queueid="10rWG2-0000dk-0E" size="717"
2009:06:16-19:23:51 xyz exim[2469]: 2009-06-16 19:23:51 10rWG2-0000dk-0E ** user@xyz.com R=dnslookup T=remote_smtp: SMTP error from remote mail server after RCPT TO:<user@xyz.com>: host mail.xyz.com [xx.***.***.xx]: 550 xx.***.***.xx blacklisted at pbl.spamhaus.org
2009:06:16-19:23:51 xyz exim[2472]: 2009-06-16 19:23:51 1MGi0N-0000ds-2a <= <> R=10rWG2-0000dk-0E U=exim P=local S=2466
2009:06:16-19:23:51 xyz exim[2469]: 2009-06-16 19:23:51 10rWG2-0000dk-0E Completed
2009:06:16-19:24:19 xyz smtpd[2467]: SCANNER[2467]: Nothing to do, exiting
***End clip log***

Thanks, Julio
Reply With Quote
  #2 (permalink)  
Old 06-17-2009, 10:50 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,317
Default

Julio, in the first line with 2009:06:16-19:23:51 xyz exim[2469], is that the IP of your Astaro or the remote IP of xyz.com?

For the record, we have several such implementations and have not see this problem, nor can I recall it appearing in the User BB.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 06-18-2009, 03:20 AM
Member
 
Join Date: May 2008
Posts: 30
Default

Quote:
Originally Posted by BAlfson View Post
Julio, in the first line with 2009:06:16-19:23:51 xyz exim[2469], is that the IP of your Astaro or the remote IP of xyz.com?

For the record, we have several such implementations and have not see this problem, nor can I recall it appearing in the User BB.

Cheers - Bob
Hi,
<host mail.xyz.com [xx.***.***.xx]: 550 xx.***.***.xx blacklisted at pbl.spamhaus.org> The first IP is the remote email host, the second ip (after 550) is part of the error message that is being sent by that host since we are doing our testing from a dynamic IP range.
I have changed the tarpit time on the exchange server to zero in case that was causing the issue, but no luck. Also the smtp transaction log on the exchange server shows the outgoing email to the astaro unit but no return of an NDR.

Funny thing is that if we instruct the astaro to use an upstream smarthost that system will attempt to deliver the email and generate an NDR and send that back to the astaro unit which will then send it back to the exchange user.
I am at a loss on what the problem may be.
Thanks, Julio
__________________
V7.504 on Dell R200 w/ Raid1 and a network of 25 users

Last edited by rxjules; 06-18-2009 at 03:22 AM.
Reply With Quote
  #4 (permalink)  
Old 06-18-2009, 05:52 PM
Member
 
Join Date: May 2008
Posts: 30
Default

Promptly this morning about 12 hours later all the NDR's were sent back to the exchange user? Does anyone know what the default delivery timeout's are for the exim email system? In exchange we can customize these times. Perhaps this could be a feature request.

Thanks, Julio
__________________
V7.504 on Dell R200 w/ Raid1 and a network of 25 users
Reply With Quote
  #5 (permalink)  
Old 06-26-2009, 01:29 PM
Junior Member
 
Join Date: Aug 2008
Posts: 7
Default

We have a similar Problem:
++++++++++++++++++++++++++++++++++++++++++++++
2009:06:26-07:58:39 mail exim[8869]: 2009-06-26 07:58:39 10Lt4V-0002Ix-2i == some.user@remotedomain.at R=dnslookup T=remote_smtp defer (-44): SMTP error from remote mail server after RCPT TO:<some.user@remotedomain.at>: host fallback.eunet.at [193.154.160.132]: 450 4.2.0 <some.user@remotedomain.at>: Recipient address rejected: Greylisted, see Postgrey Help

2009:06:26-07:58:39 mail exim[8868]: 2009-06-26 07:58:39 10Lt4U-0002Ix-2i == some.user@remotedomain.at R=dnslookup T=remote_smtp defer (-44): SMTP error from remote mail server after RCPT TO:<some.user@remotedomain.at>: host fallback.eunet.at [193.154.160.132]: 450 4.2.0 <some.user@remotedomain.at>: Recipient address rejected: Greylisted, see Postgrey Help

2009:06:26-07:59:00 mail exim[8958]: 2009-06-26 07:59:00 10Lt4U-0002Ix-2i == some.user@remotedomain.at routing defer (-51): retry time not reached

2009:06:26-07:59:00 mail exim[8959]: 2009-06-26 07:59:00 10Lt4V-0002Ix-2i == some.user@remotedomain.at routing defer (-51): retry time not reached
++++++++++++++++++++++++++++++++++++++++++++++

The Remote Site has also a Astaro ASG220 and our domain ist whitelisted. Also their domain is whitelisted on our Astaro.

What is "http://postgrey.schweikert.ch/help/manroland.at.html" all about?

Last edited by CHgeek; 06-26-2009 at 01:39 PM.
Reply With Quote
  #6 (permalink)  
Old 06-27-2009, 04:31 PM
Member
 
Join Date: May 2008
Posts: 30
Default

Hi,

Seems like the NDR's are not being returned on a consistent basis. I have to try different settings with regards to tarpitting, etc.

Thanks, Julio
__________________
V7.504 on Dell R200 w/ Raid1 and a network of 25 users
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:47 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.