Inquire whether he is using the SMTP Security Server
on the FireWall-1 platform to check outbound mail for
Content Security.
The FW-1 SMTP Security Server is not able to do
MX lookups, so if the first mail relay is not responding,
the email will not go out.
The Log Viewer will display an entry with "Connection
to final MTA failed" in the Info section.
The solution at his site would to explicitly define a SMTP service
rule before all other SMTP resource rule that would allow his
Exchange Server to send out SMTP to any destination. This would
prevent the SMTP Security Server from attempting to resolve an MX
record.
I am sure the Exchange Server can do multiple MX lookups.
Jerald Josephs
[EMAIL PROTECTED]
----- Original Message -----
From: Ng, Kenneth (US) <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, December 22, 1999 3:26 PM
Subject: Exchange with checkpoint unable to send to alt mx entries
> Hello, have any of you run into the following?:
> - I currently have two MX entries a low value that is currently refusing
> connections, and a high value that is accepting connections (we're testing
a
> new configuration for a couple of weeks).
> - Person sending to me has an Exchange server behind a Checkpoint
firewall.
>
> He says that whenever an email is attempted, that the connection is
refused
> by the low MX entry, and Exchange doesn't bother to try the other MX
entry.
> I thought I recall seeing this about a year ago, and that it was fixed.
He
> is running Exchange 5.5 SP3, so that sounds pretty recent.
>
>
>
>
****************************************************************************
*
> The information in this email is confidential and may be legally
privileged.
> It is intended solely for the addressee. Access to this email by anyone
else
> is unauthorized.
>
> If you are not the intended recipient, any disclosure, copying,
distribution
> or any action taken or omitted to be taken in reliance on it, is
prohibited
> and may be unlawful. When addressed to our clients any opinions or advice
> contained in this email are subject to the terms and conditions expressed
in
> the governing KPMG client engagement letter.
>
****************************************************************************
*
> -
> [To unsubscribe, send mail to [EMAIL PROTECTED] with
> "unsubscribe firewalls" in the body of the message.]
>
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]