Computing.Net > Forums > Windows Server 2003 > SMTP degrades Internet Performance

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

SMTP degrades Internet Performance

Reply to Message Icon

Name: Analyst
Date: October 1, 2009 at 11:42:22 Pacific
OS: Exchange 2003 SP2
CPU/Ram: XEON/1GB
Product: Microsoft Windows xp inside out
Subcategory: General
Comment:

Have strange problem where after awhile the SMTP service on the Exchange 2003 (wSP2) server will cause the Internet to slow down with dropped packets and large TTLs. Server sits behind a Sonicwall router and already replaced the router. If I stop the SMTP service Internet immediately goes back to normal. Starting the SMTP service everything is fine for awhile, then symptoms re-appear.

Did cursory virus scan and didn't turn anything up. SMTP service is configured to only accept connections from third party SPAM service (Message Labs). Sonicwall indicates only connections from the MessageLab IPs, even though it seems to have a lot of connections to MessageLabs (about 53).

I had this happen once to an Exchange Server I had running at my home office and a couple reboots seemed to fix it, but this one is still having problems.

Suggestions appreciated.

Assume that I already did an Internet search.



Sponsored Link
Ads by Google

Response Number 1
Name: wanderer
Date: October 1, 2009 at 12:09:27 Pacific
Reply:

we put in a new sonicwall as replacement for an older model. It was connected to our nortel 8500 backbone switch. We were getting broadcast storms.

Solution was to put the sonicwall on a hp lower end switch.

Broadcasts stopped. Still don't know why. I mention this because what you describe sounds like broadcast storms.


0

Response Number 2
Name: paulsep
Date: October 1, 2009 at 15:18:50 Pacific
Reply:

Have you already checked the logs on the sonicwall?


0

Response Number 3
Name: Analyst
Date: October 1, 2009 at 16:37:47 Pacific
Reply:

Yeah, I don't see anything in the logs that would explain it. It did this with the old Sonicwall and along with the new Sonicwall.

Assume that I already did an Internet search.


0

Response Number 4
Name: paulsep
Date: October 1, 2009 at 16:42:47 Pacific
Reply:

Does the server log show up any strange things?


0

Response Number 5
Name: Analyst
Date: October 1, 2009 at 17:14:37 Pacific
Reply:

Nothing out of the ordinary. I have found though the services packs both for the OS and Exchange are current, other updates are behind. I'm going to try those

Assume that I already did an Internet search.


0

Related Posts

See More



Response Number 6
Name: Phatsta
Date: October 2, 2009 at 05:23:42 Pacific
Reply:

If you're able, put another server (or just use an ordinary client with win 2003 server installed) and route all internet traffic through it temporarily, then install wireshark and log traffic to try and determine where the traffic goes, what it does and so on. For help 'decrypting' the logs (they can be both excessive and hard to interpret) see the wireshark forum. That should give you all the answers you need. It should be enough with a couple of minutes of logged traffic to determine what the problem is.


0

Response Number 7
Name: scurlaruntings
Date: October 4, 2009 at 10:05:57 Pacific
Reply:

What version of the OS are you running on the Sonicwall? If it is enhanced i can help you to trouble shoot further. Standard OS is farily limited but it can tell you at a packet level with same basic logging features as to what traffic is passing through the sonicwall. Also create a rule/access control on the Sonicwall that only allows the Exchange server to relay on 25 outbound. No other devices on the LAN should be allowed to send SMTP on 25 from the LAN other than the Exchange server.


0

Response Number 8
Name: Analyst
Date: October 4, 2009 at 11:01:26 Pacific
Reply:

Interesting thing, I remoted into the server today and it didn't seem to be having any problem. TTLs were normal and no dropped packets. Also, none of the open sessions with the MessageLabs IP's I saw before. I called MessageLabs, but they weren't very helpful. I did install Wireshark, so if it happens again I can look more indepth into it.

Thanks all.

Assume that I already did an Internet search.


0

Response Number 9
Name: Analyst
Date: October 4, 2009 at 11:03:03 Pacific
Reply:

Good suggestions, scurl. Thanks.

Assume that I already did an Internet search.


0

Sponsored Link
Ads by Google
Reply to Message Icon





Use following form to reply to current message:

Login or Register to Reply
LoginRegister


Sponsored links

Ads by Google


Results for: SMTP degrades Internet Performance

Dual Boot - Win XP Pro & Win 2003 www.computing.net/answers/windows-2003/dual-boot-win-xp-pro-amp-win-2003/222.html

counter to monitor www.computing.net/answers/windows-2003/counter-to-monitor/5094.html

Intranet/Internet Problems (DNS?) www.computing.net/answers/windows-2003/intranetinternet-problems-dns/4035.html