我无法在新的 Exchange 服务器上发送或接收电子邮件。它位于 pfSense 防火墙后面。所有必要的端口都转发到 Exchange 服务器。DNS 记录在 DNS 提供商上有效。当我检查发送连接器的日志时,我看到错误:“501 5.5.4 所需参数不存在”
这是日志文件:
2023-06-12T12:51:29.527Z,入站代理内部发送连接器,08DB6B20B9FE760E,0,,192.168.xxx.xxx:2525,,无,设置会话权限
2023-06-12T12:51:29.527Z,入站代理内部发送连接器,08DB6B20B9FE760E,1,,192.168.xxx.xxx:2525,,,尝试连接
2023-06-12T12:51:29.528Z,入站代理内部发送连接器,08DB6B20B9FE760E,2,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,+,,
2023-06-12T12:51:29.529Z,入站代理内部发送连接器,08DB6B20B9FE760E,3,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,"220 Outlook.somedomain.com Microsoft ESMTP MAIL 服务已于 2023 年 6 月 12 日星期一 15:51:29 +0300 准备就绪",
2023-06-12T12:51:29.529Z,入站代理内部发送连接器,08DB6B20B9FE760E,4,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,,,代理会话 ID 为 08DB6B20B9FE760D 的入站会话
2023-06-12T12:51:29.529Z,入站代理内部发送连接器,08DB6B20B9FE760E,5,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,EHLO Outlook.somedomain.com,
2023-06-12T12:51:29.530Z,入站代理内部发送连接器,08DB6B20B9FE760E,6,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,250 Outlook.somedomain.com Hello [192.168.xxx.xxx] SIZE PIPELINING DSN ENHANCEDSTATUSCODES STARTTLS X-ANONYMOUSTLS AUTH NTLM X-EXPS GSSAPI NTLM 8BITMIME BINARYMIME CHUNKING XEXCH50 SMTPUTF8 XRDST XSHADOWREQUEST,
2023-06-12T12:51:29.530Z,入站代理内部发送连接器,08DB6B20B9FE760E,7,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,X-ANONYMOUSTLS,
2023-06-12T12:51:29.530Z,入站代理内部发送连接器,08DB6B20B9FE760E,8,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,220 2.0.0 SMTP 服务器已准备就绪,
2023-06-12T12:51:29.532Z,入站代理内部发送连接器,08DB6B20B9FE760E,9,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,, CN=Outlook CN=Outlook 38CAA365A4DE6D9740FCB2B636FD686C 87F62D512216959E0C80550CDC811439C57CC5F4 2023-02-18T21:33:18.000Z 2028-02-18T21:33:18.000Z Outlook;Outlook.somedomain.com,远程证书主题颁发者名称序列号指纹不早于不晚主题备用名称
2023-06-12T12:51:29.532Z,入站代理内部发送连接器,08DB6B20B9FE760E,10,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,,,"TLS 协议 SP_PROT_TLS1_2_CLIENT 协商成功,使用强度为 256 位的批量加密算法 CALG_AES_256、强度为 0 位的 MAC 哈希算法 CALG_SHA_384 和强度为 384 位的密钥交换算法 CALG_ECDH_EPHEM"
2023-06-12T12:51:29.532Z,入站代理内部发送连接器,08DB6B20B9FE760E,11,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,,87F62D512216959E0C80550CDC811439C57CC5F4,Received certificate Thumbprint
2023-06-12T12:51:29.532Z,Inbound Proxy Internal Send Connector,08DB6B20B9FE760E,12,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,EHLO Outlook.somedomain.com,
2023-06-12T12:51:29.533Z,Inbound Proxy Internal Send Connector,08DB6B20B9FE760E,13,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,250 Outlook.somedomain.com Hello [192.168.xxx.xxx] SIZE PIPELINING DSN ENHANCEDSTATUSCODES AUTH NTLM LOGIN X-EXPS EXCHANGEAUTH GSSAPI NTLM X-EXCHANGEAUTH SHA256 8BITMIME BINARYMIME CHUNKING XEXCH50 SMTPUTF8 XRDST XSHADOWREQUEST XPROXY XPROXYFROM X-MESSAGECONTEXT ADRC-2.1.0.0 EPROP-1.2.0.0 XSYSPROBE XORIGFROM XMESSAGEVALUE,
2023-06-12T12:51:29.535Z,入站代理内部发送连接器,08DB6B20B9FE760E,14,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,X-EXPS EXCHANGEAUTH SHA256 ,
2023-06-12T12:51:29.535Z,入站代理内部发送连接器,08DB6B20B9FE760E,15,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,,
2023-06-12T12:51:29.541Z,入站代理内部发送连接器,08DB6B20B9FE760E,16,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,235 ,
2023-06-12T12:51:29.544Z,入站代理内部发送连接器,08DB6B20B9FE760E,17,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,*,SMTPSendEXCH50 SendRoutingHeaders SendForestHeaders SendOrganizationHeaders SMTPSendXShadow,设置会话权限
2023-06-12T12:51:29.544Z,入站代理内部发送连接器,08DB6B20B9FE760E,18,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,XPROXYFROM SID=08DB6B20B9FE760D IP=92.45.72.60 PORT=50231 DOMAIN=mgw01-107.relay01.setrow.com SEQNUM=1 PERMS=1073 AUTHSRC=Anonymous,
2023-06-12T12:51:29.545Z,入站代理内部发送连接器,08DB6B20B9FE760E,19,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,501 5.5.4 所需参数不存在,
2023-06-12T12:51:29.545Z,入站代理内部发送连接器,08DB6B20B9FE760E,20,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,>,QUIT,
2023-06-12T12:51:29.546Z,入站代理内部发送连接器,08DB6B20B9FE760E,21,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,<,221 2.0.0 服务关闭传输通道,
2023-06-12T12:51:29.546Z,入站代理内部发送连接器,08DB6B20B9FE760E,22,192.168.xxx.xxx:17302,192.168.xxx.xxx:2525,-,,本地
我的服务器试图告诉我什么?我该如何修复这个问题?
答案1
您是否能够在 Exchange 组织内发送和接收内部邮件?
发件人在尝试向您的组织发送邮件或从您的组织发送邮件后是否收到任何 NDR 消息?
您可以使用Microsoft 远程连接分析器工具,运行入站/出站 SMTP 电子邮件测试,看看是否可以得到任何线索。