Home > Microsoft Exchange Tips > Exchange Server Administration Tips > How and why to disable certain ESMTP verbs
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SERVER ADMINISTRATION TIPS

How and why to disable certain ESMTP verbs


Serdar Yegulalp
11.19.2006
Rating: --- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Some firewalls and network devices filter out certain Extended Simple Mail Transfer Protocol (ESMTP) commands or "verbs." This can break communications between Exchange 2000, Exchange 2003, and other SMTP mail servers.

If you can't or don't want to modify how traffic is being filtered, you can still get around this problem by disabling the ESMTP verbs that are being blocked by your firewalls or network devices.

Below are the ESMTP verbs that can be disabled. Some of these may be rejected explicitly by a firewall or network device.

  • TURN/ATRN
  • ETRN
  • DSN
  • ENHANCEDSTATUSCODES
  • 8bitmime
  • BINARYMIME
  • CHUNKING

The best way to make changes to your ESMTP verb list is to use the ADSI Edit utility to modify the appropriate value in Active Directory, which will then replicate to the Metabase.

  1. Open the Configuration Container on an Active Directory domain controller and navigate to Configuration -> Services -> Microsoft Exchange -> <organization> -> Administrative Groups -> <admin_group> -> Servers  -> <server> -> Protocols -> SMTP -> <virtual_server>. (Since this setting is a per-virtual-server setting, it's possible to change it for some SMTP virtual servers but not for others.)

  2. View the msExchSmtpInboundCommandSupportOptions property.

  3. Select Edit Attribute.

  4. The default value for this attribute is 3503297 (decimal). To figure out which options to disable, take this number and subtract the corresponding decimal values for each option:

    DSN: 64
    ETRN: 128
    TURN/ATRN: 1024
    ENHANCEDSTATUSCODES: 4096
    CHUNKING: 1048576
    BINARYMIME: 2097152
    8bitmime: 4194304

    For instance, if you only want to disable CHUNKING, use 2454721 (3503297 minus 1048576). To disable DSN and CHUNKING, you'd use 2454657 (3503297minus 64 minus1048576).

  5. Apply the changes. (Note that the changes will need to be replicated from your domain controller before they take effect.)

This process is described in slightly more detail in Microsoft Knowledge Base article 257569, "How to turn off ESMTP verbs in Exchange 2000 Server and in Exchange Server 2003."

One command often blocked by network boxes is actually not on this list -- BDAT. This ESMTP verb in turn attempts to invoke CHUNKING. In such a case, you probably will need to turn off CHUNKING until another workaround can be found.

A couple important side notes to keep in mind:

  • If you make these changes, they should only be done in a provisional way. Also, you should document them explicitly so they can be undone when they are no longer needed -- for instance, after you update your network devices to allow these ESMTP verbs transparently.

  • It's always best to try and update the problematic network device first (if that's the source of the problem) before disabling any ESMTP verbs, since it can have unwanted side effects.

About the author: Serdar Yegulalp is editor of the Windows Power Users Newsletter.

Do you have comments on this tip? Let us know.

Related information from SearchExchange.com:

  • FAQ: Exchange Server non-delivery reports (NDRs)
  • Tip: Beware of firewalls that block Exchange's SMTP/POP3 communications
  • Tip: Firewall policies and SMTP line lengths
  • Tip: How HTTP verbs can 'hang' Outlook Web Access
  • Expert Advice: Cisco PIX firewall causing Exchange connectivity problems
  • Step-by-Step Guide: How to use ISA Server as an SMTP filter
  • Reference Center: Firewall tips and resources

    Please let others know how useful this tip was via the rating scale below. Do you have a useful Exchange Server or Microsoft Outlook tip, timesaver or workaround to share? Submit it to SearchExchange.com. If we publish it, we'll send you a nifty thank-you gift.

    Rate this Tip
    To rate tips, you must be a member of SearchExchange.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Exchange Server Administration Tips
    Remove Exchange 2003 objects from AD to install Exchange 2010
    Is your Exchange 2007 hub transport server healthy?
    Avoid Outlook 2007 performance issues during repairs
    Developing an Exchange 2007 server role DR plan
    How DSAccess service improves Exchange Server 2007 reliability
    An introduction to the Exchange Remote Connectivity Analyzer tool
    Monitor Exchange 2007 with disk- and RPC-related counters
    DPM 2007 replica inconsistencies in Exchange databases
    Track Exchange 2007 mailbox server health using database counters
    Digging deeper into Exchange Server 2010

    Microsoft Exchange Server 2003
    Remove Exchange 2003 objects from AD to install Exchange 2010
    Leapfrogging from Exchange 2003 to Exchange 2010
    Top 5 Exchange ActiveSync tips
    Exchange Mailbag: POP3 settings and Outlook issues
    Migrating to Exchange 2007 with correct permissions
    Problems receiving email from outside a Exchange Server 2003 domain
    Exchange admins: Is it time to rethink your email address policy?
    Exchange Server 2003 collects email from only specific POP3 domains
    Changing email address formats in Exchange Server 2003
    Should you remove .STM files from Exchange Server 2003?
    Microsoft Exchange Server 2003 Research

    ISA Server and Firewalls for Microsoft Exchange Server
    Top 5 Exchange mobile tips of 2008
    Microsoft Exchange Server security dos and don'ts
    Windows SBS and Exchange Server security configuration best practices
    Why Exchange ActiveSync fails with NAT firewalls
    Deploying ISA Server as a firewall for Exchange Server mobile devices
    Adjust your firewall to avoid Exchange 2007 Direct Push failures
    OWA stops working from external network connection
    Enhance OWA logon security using Microsoft ISA Server
    Firewall problems with Exchange Server 2007 email attachments
    Creating an ethical firewall in Exchange Server 2007

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    reverse proxy server  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Email Server Solutions: Exchange 2007, Exchange 2003, Exchange 2000, SharePoint
    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts