554 Policy violation. Email Session ID: {4F4807CA-17-2FEA8C0-1FFFF}

I was working with my friend on exchange server 2010 mail flow issue. He is not able to send email outside on the internet, but he could receive email from outside. Everything was working fine but all of a sudden it stopped working.

Exchange server is running in mixed environment with exchange server 2007 and 2010


I tried to send email using telnet but it failed. Checked the event viewer for any information but surprisingly there were not event generated related to the issue. It is happening to all the users on both exchange 2007 and exchange 2010 server.

Checked the Queue Viewer on 2010 server and got the below information which was very helpful in terms of troubleshooting.
Queue_HUBTransport-LAN - CopyWe had a Check Point firewall between Exchange 2010 Hub Transport and EDGE server.
After looking into Check Point firewall, I found that SMTP inspection is ON on it.
But it worked fine in the past without any issue. All though I didn’t checked the SMTP inspection on the Check Point server in past, hence I do not know what was the status of it, was it ON or OFF.
Turned OFF the SMTP Inspection on Check Point firewall and checked the mail flow and it started working fine.
The only thing I can think of for SMTP Inspection got turned ON would be any update for Check Point or my Security guy must have done it without knowing the impact of it on exchange server Winking smile
Reference article to turn Off SMTP Inspection:
http://technet.microsoft.com/en-us/library/dd277550(v=exchg.80).aspx
Cheers,

Leave a Reply

EXCHANGE RANGER