03-30-2020 05:47 AM
I am having a problem with multiple hosts being marked as down, with more coming approximately once a week.
It is very annoying for my users and reflects badly upon me, as an admin and advocate for us needing this product.
What will happen is:
1. Sent mails will stay in the queue and not get sent. If I don't do anything, users will get a mail after 3 days with message too old.
Looking in the ESA I see the hosts as down. (screenshot 1)
Cli tells me this:
hoststatus tinsillo.com
Host mail status for: 'tinsillo.com'
Status as of: Mon Mar 30 10:43:06 2020 -02
Host up/down: down
Counters:
Queue
Soft Bounced Events 0
Completion
Completed Recipients 0
Hard Bounced Recipients 0
DNS Hard Bounces 0
5XX Hard Bounces 0
Filter Hard Bounces 0
Expired Hard Bounces 0
Other Hard Bounces 0
Delivered Recipients 0
Deleted Recipients 0
Gauges:
Queue
Active Recipients 1
Unattempted Recipients 1
Attempted Recipients 0
Connections
Current Outbound Connections 0
Pending Outbound Connections 0
Oldest Message 10 hours 42 mins 53 secs
Last Activity Mon Mar 30 10:21:36 2020 -02
Ordered IP addresses: (expiring at Mon Mar 30 17:03:20 2020 -02)
Preference IPs
5 23.106.125.178
MX Records:
Preference TTL Hostname
5 6h20m13s mail.tinsillo.com
I have allowed all encryption algorithms in ssl settings, as I suspect a mismatch in algorithms.
If I go to ESA -> Mail policies -> destination controls -> and set TLS to none
The hoststatus changes to UP and mails go through.
I do not think it is optimal to manually whitelist domains like this, and having to disable TLS is even worse.
Can you please help me to diagnose and fix this?
Solved! Go to Solution.
03-30-2020 06:30 AM
03-30-2020 06:13 AM
03-30-2020 06:43 AM
My default action is preferred, so nothing is tls required.
I sadly can't easily packet capture as I am on CES.
03-30-2020 06:49 AM
03-30-2020 06:30 AM
03-30-2020 07:01 AM
but will the algos matter if it set to default preferred?
I mean if they dont agree shouldnt it just go to no tls?
03-30-2020 07:09 AM
03-30-2020 07:50 AM
do you know which log to grep for tls negotiations?
03-30-2020 08:04 AM
03-30-2020 07:59 AM
After setting algos to your suggestion, testing one of the hosts succeded with prefer.
I am now suspecting it to be one of those problems where one algo will fail and the parts are unable to renegotiate and standoff instead.
I will test further later.
03-31-2020 06:05 AM
Yes all of my problem domains are now at hoststatus up and receiving mail.
Until further I hope this has resolved my problem, though I hate having to implement a workaround without a smoking gun.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide