SOLVED

Hybrid Exchange change of SMTP relay connector

%3CLINGO-SUB%20id%3D%22lingo-sub-1425444%22%20slang%3D%22en-US%22%3EHybrid%20Exchange%20change%20of%20SMTP%20relay%20connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1425444%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20we%20have%20Hybrid%20Exchange%20environment%2C%20with%20few%202010%20Exchange%20boxes%20on-prem%2C%201x%20Exchange%202016%20on-prem%20(as%20the%20hybrid)%20and%20O365%20tenant.%3C%2FP%3E%3CP%3EUntil%20now%20we%20were%20using%20one%20of%20the%20EX2010%20boxes%20as%20main%20smtp%20relay%20and%20it%60s%20working%20great.%20Now%20we%20want%20to%20switch%20that%20role%20and%20move%20it%20to%20the%20hybrid%202016%20Exchange.%20To%20beused%20by%20the%20internal%20scan2email%2C%20apps%2C%20etc%20for%20sending%20anonym.%3C%2FP%3E%3CP%3EAll%20FW%20rules%20are%20configured%20correctly.%3C%2FP%3E%3CP%3EThe%20ext%20IP%20address%20of%20the%202016%20box%20is%20added%20as%20trusted%20connector%20in%20EXO%3C%2FP%3E%3CP%3EI%20have%20send%2Frecieve%20connectors%20configured%20on%20the%202016%20box%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20problem%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20go%20and%20test%20telnet%20(EXO%20ext%20IP)%2025%20-%20got%20connection%20and%20response%20and%20all%20is%20nice%20and%20shiny%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20try%20to%20do%20the%20same%20from%20the%20hybrid%202016%20box%20-%20got%20connection%20open%20and%20blank%20screen.%20Stays%20for%20about%2060%20seconds%20and%20then%20Connection%20closed%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20found%20in%20the%20logs%20some%20errors%20saying%20socket%20error%20-%20but%20it%20doesnt%20make%20sense%20because%20the%20fw%20shows%20all%20connections%20as%20allowed%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%3F%20I%20cant%20find%20any%20other%20reason%20why%20it%20would%20not%20establish%20smtp%20connection%20to%20the%20EXO%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1425444%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3E2010%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3E2016%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1425948%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20change%20of%20SMTP%20relay%20connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1425948%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F640620%22%20target%3D%22_blank%22%3E%40Anton5032%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHmm%2C%20that's%20interesting.%20%26nbsp%3BAre%20you%20able%20to%20share%20a%20screenshot%20of%20the%20receive%20connector%20you%20have%20created%20on%20your%20Exchange%202016%20server%20please%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20could%20you%20share%20the%20socket%20error%20you%20are%20seeing%20too%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1432421%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20change%20of%20SMTP%20relay%20connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1432421%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3Ethanks%20for%20the%20reply%3C%2FP%3E%3CP%3Ethis%20is%20the%20receive%20connector%20(screenshot)%20and%20under%20security%20we%20have%20marked%20ONLY%20-%20Anonymous%3C%2FP%3E%3CP%3EScoping%20is%20the%20internal%20printer%20network%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Anton5032_0-1591061635922.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F195857i5F980E47764723E4%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Anton5032_0-1591061635922.png%22%20alt%3D%22Anton5032_0-1591061635922.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooks%20like%20the%20receive%20connector%20on%20the%20Exchange%202016%20is%20ok%2C%20but%20then%20if%20try%20to%20open%20SMTP%2025%20to%20Outlook.office.com%20from%20the%20Exchange%202016%20all%20I%20am%20getting%20is%20blank%20screen%20and%20nothing%20else.%20When%20I%20try%20to%20do%20the%20same%20from%20the%20old%202010%20Exchange%20box%20it%20all%20works%20perfectly.%20As%20I%20said%20on%20the%20FW%20both%20boxes%20have%20identical%20rules.%20Not%20sure%20why%20EXCH2016%20-%26gt%3B%20Outlook.office.com%3A25%20not%20working%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1432594%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20change%20of%20SMTP%20relay%20connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1432594%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F640620%22%20target%3D%22_blank%22%3E%40Anton5032%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhenever%20I%20setup%20a%20connector%20for%20this%20purpose%20on%20an%20Exchange%202016%20Server%2C%20I%20always%20set%20the%20security%20tab%20options%20as%20follows%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Screenshot%202020-06-02%20at%2006.42.46.png%22%20style%3D%22width%3A%20998px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F195870i977729F7380E5946%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Screenshot%202020-06-02%20at%2006.42.46.png%22%20alt%3D%22Screenshot%202020-06-02%20at%2006.42.46.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EI%20would%20definitely%20double%20and%20triple%20check%20your%20firewall%20rules%20too.%20%26nbsp%3BDo%20you%20definitely%20have%20the%20Exchange%20Online%20IP's%20all%20allowed%20for%20the%20Exchange%202016%20server%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1434787%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20change%20of%20SMTP%20relay%20connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1434787%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETHANK%20YOU!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20definitely%20did%20the%20trick%2C%20although%20now%20it%20looks%20like%20whoever%20created%20the%20send%20connector%20didnt%20do%20the%20work%20right%20-%20it%20is%20only%20relaying%20emails%20to%20internally%20and%20if%20try%20to%20send%20externally%20(ie%3A%20gmail)%20-%20nothing%20happens.%3C%2FP%3E%3CP%3EI%20can%20see%20there%20is%20a%20separate%20send%20connector%20for%20that%202016%20box%20and%20another%20one%20which%20serves%20the%20on-prem%20(which%20obviously%20works%20fine%20at%20the%20moment).%20So%2C%20I%20am%20not%20sure%20how%20the%202016%20send%20must%20looking.%3C%2FP%3E%3CP%3ECurrent%20config%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Edelivery%3A%3C%2FP%3E%3CP%3ERoute%20via%20smart%20hosts%20(address%20of%20our%20securemx)%3C%2FP%3E%3CP%3ESmart%20host%20auth%3A%20NONE%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EScoping%3A%3C%2FP%3E%3CP%3EAddress%20Space%20-%20SMTP%20*%3C%2FP%3E%3CP%3ESource%20server%3A%20ADDRESS%20of%20the%202016%20Exch%20box%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20will%20be%20greatly%20appreacited!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1441497%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20change%20of%20SMTP%20relay%20connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1441497%22%20slang%3D%22en-US%22%3E%3CP%3EFound%20the%20problem!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFW%20issue%20-%20someone%20forgot%20to%20fix%20the%20src%20ip%20masq%20and%20the%20requests%20were%20going%20with%20the%20default%20ext%20ip%20instead%20the%20dedicated%20one%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20help!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi All

 

So we have Hybrid Exchange environment, with few 2010 Exchange boxes on-prem, 1x Exchange 2016 on-prem (as the hybrid) and O365 tenant.

Until now we were using one of the EX2010 boxes as main smtp relay and it`s working great. Now we want to switch that role and move it to the hybrid 2016 Exchange. To beused by the internal scan2email, apps, etc for sending anonym.

All FW rules are configured correctly.

The ext IP address of the 2016 box is added as trusted connector in EXO

I have send/recieve connectors configured on the 2016 box

 

The problem:

 

If I go and test telnet (EXO ext IP) 25 - from within the EX2010 box, I got connection and response and all is nice and shiny

 

If I try to do the same from the hybrid 2016 box - got connection open and blank screen. Stays for about 60 seconds and then Connection closed. No need to say that it is not forwarding anything if I try lets sat scan2email from one of the printers.

 

I found in the logs some errors saying socket error - but it doesnt make sense because the fw shows all connections as allowed and as I said the fw rules are the same for EX2010 and EX2016 boxes, the difference is that they are presented with different ext IPs, but both of them added as trusted in EXO Admin

 

Any ideas? I cant find any other reason why it would not establish smtp connection to the EXO ?

5 Replies
Highlighted

@Anton5032 

 

Hmm, that's interesting.  Are you able to share a screenshot of the receive connector you have created on your Exchange 2016 server please?

 

Also, could you share the socket error you are seeing too?

Highlighted

@PeterRisingthanks for the reply

this is the receive connector (screenshot) and under security we have marked ONLY - Anonymous

Scoping is the internal printer network

Anton5032_0-1591061635922.png

 

Looks like the receive connector on the Exchange 2016 is ok, but then if try to open SMTP 25 to Outlook.office.com from the Exchange 2016 all I am getting is blank screen and nothing else. When I try to do the same from the old 2010 Exchange box it all works perfectly. As I said on the FW both boxes have identical rules. Not sure why EXCH2016 -> Outlook.office.com:25 not working

Highlighted
Best Response confirmed by Anton5032 (Occasional Contributor)
Solution

@Anton5032 

 

Whenever I setup a connector for this purpose on an Exchange 2016 Server, I always set the security tab options as follows;

 

Screenshot 2020-06-02 at 06.42.46.png

I would definitely double and triple check your firewall rules too.  Do you definitely have the Exchange Online IP's all allowed for the Exchange 2016 server?

Highlighted

@PeterRising 

THANK YOU!

 

That definitely did the trick, although now it looks like whoever created the send connector didnt do the work right - it is only relaying emails to internally and if try to send externally (ie: gmail) - nothing happens.

I can see there is a separate send connector for that 2016 box and another one which serves the on-prem (which obviously works fine at the moment). So, I am not sure how the 2016 send must looking.

Current config:

 

delivery:

Route via smart hosts (address of our securemx)

Smart host auth: NONE

 

Scoping:

Address Space - SMTP *

Source server: ADDRESS of the 2016 Exch box

 

 

Any help will be greatly appreacited!

 

 

Highlighted

Found the problem!

 

FW issue - someone forgot to fix the src ip masq and the requests were going with the default ext ip instead the dedicated one

 

Thanks for the help!