Hello,
We have a PMG cluster (just one master plus one node) that is been running for a few years now, works great. It handles mail for about 12 domains, and relays it to Office 365 exchange.
Just recently after upgrading to PMG 7.1-4, we started seeing some weirdness in mail between two domains. They're both in Office 365, but totally separate tenants/exchange environments. Different companies entirely. They were working fine before.
Basically, we get an error on mails between the two domains that says "Hop count exceeded - possible mail loop ATTR1".
In PMG logs, we can see the mail looping several times before Exchange gives up and kills it.
In the sending Exchange server's message trace, the first "try" has From IP of the client sending it, and a To IP of our PMG server. Subsequent tries have a From IP and a To IP of the PMG mail server. The Exchange server that should be receiving it never has it showing up in the log. Basically, on Exchange's end, it looks like PMG is just bouncing it back to the originating server instead of relaying it to the proper server.
This doesn't happen on the other domains on our PMG server, and it doesn't happen from external services (ie: gmail.) Only between these two domains we have on our PMG gateway.
For now, so the two entities can communicate, we've moved their MX records to go straight to Microsoft instead of routing through PMG, but this is not our desired outcome.
How can I begin to troubleshoot this further?
We have a PMG cluster (just one master plus one node) that is been running for a few years now, works great. It handles mail for about 12 domains, and relays it to Office 365 exchange.
Just recently after upgrading to PMG 7.1-4, we started seeing some weirdness in mail between two domains. They're both in Office 365, but totally separate tenants/exchange environments. Different companies entirely. They were working fine before.
Basically, we get an error on mails between the two domains that says "Hop count exceeded - possible mail loop ATTR1".
In PMG logs, we can see the mail looping several times before Exchange gives up and kills it.
In the sending Exchange server's message trace, the first "try" has From IP of the client sending it, and a To IP of our PMG server. Subsequent tries have a From IP and a To IP of the PMG mail server. The Exchange server that should be receiving it never has it showing up in the log. Basically, on Exchange's end, it looks like PMG is just bouncing it back to the originating server instead of relaying it to the proper server.
This doesn't happen on the other domains on our PMG server, and it doesn't happen from external services (ie: gmail.) Only between these two domains we have on our PMG gateway.
For now, so the two entities can communicate, we've moved their MX records to go straight to Microsoft instead of routing through PMG, but this is not our desired outcome.
How can I begin to troubleshoot this further?