ORF反垃圾邮件系统

邮件服务器-邮件系统-邮件技术论坛(BBS)

 找回密码
 会员注册
查看: 11669|回复: 10
打印 上一主题 下一主题

[讨论] Exchange 2003 队列堵塞,导致服务器瘫痪!!!

[复制链接]
跳转到指定楼层
顶楼
发表于 2007-3-28 10:57:28 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
最近一段时间,公司的邮件服务器,总会有一段时间,拒绝工作,打开ESM一看,队列堵了400多个,还不多!嘿嘿!
为了让公司的工作正常运行,我采取了最简洁的方法:重启smtp服务,然后看着队列一个一个出去!心才稍微舒坦点!

这样的工作,这个月我做了两次,我怀疑是不是我的邮件服务器出问题了!想想也是,总得找个原因吧,不能就这样糊里糊涂的重启下去吧!万一哪天重启也不行,那不就歇菜了吗?

所以,我抓了些日志出来,请大家一道帮我分析分析?

首先说明一下网络环境:

       Windows2003(english)+ Exchange2003(english)

       GFI Mail Essentials For Exchange/SMTP version 10.1

       以前这种情况也发生过,但不像现在这样频繁,首先我猜想是不是病毒在作怪!

下面是些日志:大家一道分析分析!

       1)Application log

        
            Event Type: Warning
Event Source: MSExchangeTransport
Event Category: NDR
Event ID: 3006
Date:  3/28/2007
Time:  9:28:41 AM
User:  N/A
Computer: server
Description:
A non-delivery report with a status code of 4.4.7 was generated for recipient rfc822;yokoya.dj@aa.com (Message-ID <628FD2C68FEF7741935D95A150B6E0C0C14A62@server.bb.com>).   
Cause: Message in queue has expired.  The sending server tried to relay or deliver the message but the action could not be completed before the message expired.   
Solution: This message usually indicates a problem on the receiving server.  Check the validity of recipients address and verify that the receiving server is configured to receive messages correctly.  Resending the message will place it again in the queue, if the receiving server is up, message delivery will succeed.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: d1 02 04 c0                 

Event Type: Warning
Event Source: MSExchangeTransport
Event Category: Connection Manager
Event ID: 4006
Date:  3/28/2007
Time:  9:27:00 AM
User:  N/A
Computer: server
Description:
Message delivery to the host '60.28.13.150' failed while delivering to the remote domain  'bb.com' for the following reason: The remote server did not respond to a connection attempt.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: d2 02 04 c0              

Event Type: Warning
Event Source: MSExchangeTransport
Event Category: NDR
Event ID: 3014
Date:  3/28/2007
Time:  9:26:27 AM
User:  N/A
Computer: server
Description:
A non-delivery report with a status code of 5.2.3 was generated for recipient rfc822;lim@aa.com (Message-ID <628FD2C68FEF7741935D95A150B6E0C0C1504A@server.bb.com>).   
Cause: The message size was large or the  local quota exceeded.  For example, remote Exchange user might have delivery restrictions set with maximum incoming message size.   
Solution: Check access permissions as well as the message size.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: MSExchangeTransport
Event Category: SMTP Protocol
Event ID: 7002
Date:  3/28/2007
Time:  9:23:01 AM
User:  N/A
Computer: server
Description:
This is an SMTP protocol warning log for virtual server ID 2, connection #147. The remote host "141.27.2.8", responded to the SMTP command "rcpt" with "450 <yongjian.yu@aa.com>: Recipient address rejected: Policy Rejection:   ". The full command sent was "RCPT TO:<yongjian.yu@aa.com>  ".  This may cause the connection to fail.
For more information, click http://www.microsoft.com/contentredirect.asp.


Event Type: Warning
Event Source: MSExchangeTransport
Event Category: NDR
Event ID: 3014
Date:  3/28/2007
Time:  9:16:12 AM
User:  N/A
Computer: server
Description:
A non-delivery report with a status code of 5.2.3 was generated for recipient rfc822;market@aa.com (Message-ID <628FD2C68FEF7741935D95A150B6E0C0C15036@server.bb.com>).   
Cause: The message size was large or the  local quota exceeded.  For example, remote Exchange user might have delivery restrictions set with maximum incoming message size.   
Solution: Check access permissions as well as the message size.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: MSExchangeTransport
Event Category: SMTP Protocol
Event ID: 7010
Date:  3/28/2007
Time:  8:36:41 AM
User:  N/A
Computer: server
Description:
This is an SMTP protocol log for virtual server ID 2, connection #130. The client at "28.10.131.56" sent a "xexch50" command, and the SMTP server responded with "504 Need to authenticate first  ". The full command sent was "xexch50 2708 2".  This will probably cause the connection to fail.
For more information, click http://www.microsoft.com/contentredirect.asp.


     2)System Log



Event Type: Warning
Event Source: smtpsvc
Event Category: None
Event ID: 2012
Date:  3/27/2007
Time:  9:47:11 PM
User:  N/A
Computer: server
Description:
SMTP could not connect to the DNS server '202.96.209.133'. The protocol used was 'UDP'. It may be down or inaccessible.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: d5 04 00 00               

Event Type: Error
Event Source: smtpsvc
Event Category: None
Event ID: 2013
Date:  3/27/2007
Time:  8:14:48 PM
User:  N/A
Computer: server
Description:
SMTP could not connect to any DNS server. Either none are configured, or all are down.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 7c 26 00 00               |&..   

Event Type: Warning
Event Source: DNS
Event Category: None
Event ID: 3000
Date:  3/27/2007
Time:  8:52:10 AM
User:  N/A
Computer: server
Description:
The DNS server has encountered numerous run-time events. To determine the initial cause of these run-time events, examine the DNS server event log entries that precede this event. To prevent the DNS server from filling the event log too quickly, subsequent events with Event IDs higher than 3000 will be suppressed until events are no longer being generated at a high rate.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



    3)邮件的跟踪截图

[ 本帖最后由 benet-panjian 于 2007-3-28 13:17 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?会员注册

x
沙发
 楼主| 发表于 2007-3-28 11:42:13 | 只看该作者
呵呵,没人想跟个帖吗?
藤椅
 楼主| 发表于 2007-3-28 11:45:43 | 只看该作者

Exchange 2003 队列堵塞,导致服务器瘫痪!!!

呵呵,没人跟帖呀!后来我试了下,将NDR关了,Scanmail也关了!
到最后队列里还剩38个,过了一个晚上也出不去,不知是啥原因!!

切盼大家踊跃发言!
板凳
发表于 2007-3-28 12:30:11 | 只看该作者
SMTP could not connect to the DNS server '202.96.209.133'. The protocol used was 'UDP'. It may be down or inaccessible.
---检查一下,你使用的dns ip是否解析正常?会不会是邮件发不出去.
报纸
 楼主| 发表于 2007-3-28 13:08:26 | 只看该作者
DNS 的解析一切正常,能够使用NSLOOKUP解析外部的域名!

现在收发邮件一切正常!

就是还有38只队列始终出不去,很纳闷!

刚刚查看了其中一个队列的收件人邮件地址为nalbastiaanragashej@bastiaanragas.net;我怀疑此地址是否存在,或者是否被别人中继了呢!

期待中!!!
地板
发表于 2007-3-28 15:05:56 | 只看该作者
你可以看看能不能nslookup这些域名的信息就知道了.不一定完全是因为被中继,

1.有可能是垃圾邮件发过来,因本地没有收件人,然后退信,但是对方地址错误造成的NDR.最好是在收件人过滤中把不在目录中的收件人过滤.

2.然后就要检查你是否开启了中继了.

3.是否用户端中了邮件木马
7
发表于 2007-3-30 13:35:38 | 只看该作者
被中继了拉!38封是正常邮件吗?你确认吗?反向解析做过吗?
8
 楼主| 发表于 2007-3-30 14:16:12 | 只看该作者
都是一些正常的邮件!

没做反向解析!

今天我突然发现,邮件又收发不了,最后只好手动重启SMTP了;同时我在Current session中,发现竟然存在几个IP的链接,不知此种情况,是否正常?后来,我全部手动中断了!

[ 本帖最后由 benet-panjian 于 2007-3-30 14:20 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?会员注册

x
9
发表于 2007-3-31 09:20:26 | 只看该作者
que.jpg图中有很多不能解释的域名,都是提示连接错误,同时你关闭NDR可以发出大部分的邮件,很说明你的服务在发送大量的垃圾邮件,有被中继的可能,当然,自身客户端中端发垃圾邮件也是可能的。
10
 楼主| 发表于 2007-3-31 15:13:05 | 只看该作者
的确如楼上所讲,因为公司的性质是搞信息咨询的,销售人员会经常给各种大公司发送一些培训.产品等方面的信息!

我想:的确存在着自身发送垃圾邮件的可能性吧!

[ 本帖最后由 benet-panjian 于 2007-3-31 15:14 编辑 ]
您需要登录后才可以回帖 登录 | 会员注册

本版积分规则

小黑屋|手机版|Archiver|邮件技术资讯网

GMT+8, 2024-12-24 02:47

Powered by Discuz! X3.2

© 2001-2016 Comsenz Inc.

本论坛为非盈利中立机构,所有言论属发表者个人意见,不代表本论坛立场。内容所涉及版权和法律相关事宜请参考各自所有者的条款。
如认定侵犯了您权利,请联系我们。本论坛原创内容请联系后再行转载并务必保留我站信息。此声明修改不另行通知,保留最终解释权。
*本论坛会员专属QQ群:邮件技术资讯网会员QQ群
*本论坛会员备用QQ群:邮件技术资讯网备用群

快速回复 返回顶部 返回列表