ERROR:
LED=441 4.4.1 Error encountered while communicating with the Primary Target IP address (Failed to connect. Winsock error code: 10060, Win32 error code 10060. Attempted failover to alternate host)
You see E-Mail in the Queue and have no E-Mail flow on Exchange 2013:
This can have following error sources:
-
DNS Settings of NIC (Server)
-
DNS Settings of Exchange itself (Not the OS DNS the under /ECP)
-
HIDDEN OLD NIC as example replaced or in VM
-
RECEIVE CONNECTOR with DUBLETTE criteria (SELF MADE which reflects built in CRITERIA)
Here is how to resolve in steps:
-
Check if all AUTOMATIC Services from Exchange are running (Exchange 2013 CAN take Services DOWN if he thinks something is wrong)
-
Restart full Exchange or all *TRANSPORT* Services
-
Check your DNS Settings in Exchange ITSELF (/ECP) and on your NIC’s (https://www.butsch.ch/post/Exchange-2013-451-470-Temporary-Server-errors-Please-Try-Again-Later-PRX.aspx
-
Check if you have hidden NIC’s (https://www.butsch.ch/post/W7-Show-hidden-Hardware-devices.aspx)
-
Receive Connector > Check all additional RECEIVE Connector and IF they have common criteria with OTHER built in receive connector. If worst CASE both have the MANY identical Criteria on your SELF MADE you may have to change from Port 25 to 26. Test by removing the SELF MADE receive connector and Restart the Exchange. If Mail Flow is ok then it was the connector you made. (https://www.butsch.ch/post/Exchange-2007-2010-How-to-RELAY-ANONYMOUS-for-clients-or-Servers-(GermanEnglish).aspx) < THIS has not changed from 2007/2012 in terms of selection through Criteria.
Look out for IP ranges, which are in Connector two times AND have the same setting on PORT, Authentication etc. If Exchange DOES not KNOW, WHICH receive connector to take/use he will end up in a loop and may take down services in 2013 if this happen many times.
Some sample Connector Criteria:
Sample wrong Connector range which covers the “OTHER” Exchange Server which would have IP 192.168.200.10 and thus Exchange would FALSE use this connector for INTERNAL MAIL FLOW (Exchange Mail Flow). Beside this would open MAIL RELAY for the Full VLAN segment in Ransomware days.