Community Discussions and Support
Windows server 2008 + Mercury

I hope you can help because this stuff goes beyond my knowledge and

it's going to take lots of time for me to solve this, if ever.

The lack of connection to port 110 can be caused by:

1.   MercuryP is not running and bound to port 110.

2.   Port 110 to the local system is being blocked by the Windows firewall.  Turn off the firewall and try again to test.

3.   MercuryP is blocking the IP address.  Allow the local addresses in the MercuryP connection control and whitelist them.

 

 

 

<blockquote>I hope you can help because this stuff goes beyond my knowledge and it's going to take lots of time for me to solve this, if ever.</blockquote><p>The lack of connection to port 110 can be caused by:</p><p>1.   MercuryP is not running and bound to port 110. </p><p>2.   Port 110 to the local system is being blocked by the Windows firewall.  Turn off the firewall and try again to test. </p><p>3.   MercuryP is blocking the IP address.  Allow the local addresses in the MercuryP connection control and whitelist them.</p><p> </p><p> </p><p> </p>

First of all, I want to thank all moderators and people involved with this forum for finding solutions to all of our problems.  It's amazing how fast you guys respond to help us. 

I have installed and set up the latest Mercury to work with thunderbird on our local windows 2008 server (30 clients).  After trying to log onto the server with thunderbird, the damn thing always says I'm unable to connect to the server.  In a previous post this question also arose where it turned out to be a firewall issue.  Since the firewall is completely down, rules have been allowed for mercury and clients, ports 143-110-25 stay open, and there's no other virus software, I strongly doubt this is the problem. 

I've also been able to run the telnet command successfully, where the client has even giving me the version of mercury as output.

The DNS-server is configured correctly since I can access all shares and run everything without a problem except thunderbird (also latest version).

I am missing something here, but after a long time I still don't know what it is.

 Another problem is that I'm installing Windows Server 2008 in the same computer case as Windows Server 2003 is running now in the office, so I won't be able to try suggestions until all employees are out.

 regards,

Jim

 

<P>First of all, I want to thank all moderators and people involved with this forum for finding solutions to all of our problems.  It's amazing how fast you guys respond to help us. </P> <P>I have installed and set up the latest Mercury to work with thunderbird on our local windows 2008 server (30 clients).  After trying to log onto the server with thunderbird, the damn thing always says I'm unable to connect to the server.  In a previous post this question also arose where it turned out to be a firewall issue.  Since the firewall is completely down, rules have been allowed for mercury and clients, ports 143-110-25 stay open, and there's no other virus software, I strongly doubt this is the problem.  </P> <P>I've also been able to run the telnet command successfully, where the client has even giving me the version of mercury as output.</P> <P>The DNS-server is configured correctly since I can access all shares and run everything without a problem except thunderbird (also latest version).</P> <P>I am missing something here, but after a long time I still don't know what it is.</P> <P> Another problem is that I'm installing Windows Server 2008 in the same computer case as Windows Server 2003 is running now in the office, so I won't be able to try suggestions until all employees are out.</P> <P> regards,</P> <P>Jim</P> <P mce_keep="true"> </P>

From what you have said, the Merc console window for whichever protocol you are testing should show the telnet connection but not the thunderbird attempt.

Did you telnet to the same server name as in the thunderbird config? (not by IP address)

[quote]The DNS-server is configured correctly since I can access all shares

and run everything without a problem except thunderbird (also latest

version).[/quote]

Not necessarily, windows shares use NETBIOS lookups before resorting to DNS lookups only if that fails.

[quote]Since the firewall is completely down, rules have been allowed for

mercury and clients, ports 143-110-25 stay open, and there's no other

virus software, I strongly doubt this is the problem. [/quote]

I strongly suspect this IS the problem. [:P]

Anyway, the answer lies in the difference between your telnet & thunderbird on the client, as anything blocking on the server would not be able to tell the difference.

<p>From what you have said, the Merc console window for whichever protocol you are testing should show the telnet connection but not the thunderbird attempt.</p><p>Did you telnet to the same server name as in the thunderbird config? (not by IP address)</p><p>[quote]The DNS-server is configured correctly since I can access all shares and run everything without a problem except thunderbird (also latest version).[/quote]</p><p>Not necessarily, windows shares use NETBIOS lookups before resorting to DNS lookups only if that fails. </p><p>[quote]Since the firewall is completely down, rules have been allowed for mercury and clients, ports 143-110-25 stay open, and there's no other virus software, I strongly doubt this is the problem. [/quote]</p><p>I strongly suspect this IS the problem. [:P]</p><p>Anyway, the answer lies in the difference between your telnet & thunderbird on the client, as anything blocking on the server would not be able to tell the difference. </p>

Thx for the reply

You seem to know stuff :)

I tried telnet with putty before but it didn't seem to work.  I must be missing something here as well. 

Can the DHCP-server work flawlessly with a badly configured DNS-server?  

In Thunderbird my server name is configured by IP-address.  Should I try telnetting by name, would that make any difference?

Any hints?

<P>Thx for the reply</P> <P>You seem to know stuff :)</P> <P>I tried telnet with putty before but it didn't seem to work.  I must be missing something here as well. </P> <P>Can the DHCP-server work flawlessly with a badly configured DNS-server?  </P> <P>In Thunderbird my server name is configured by IP-address.  Should I try telnetting by name, would that make any difference?</P> <P>Any hints?</P>

[quote user="Jim Pow"]Thx for the reply You seem to know stuff :)

I tried telnet with putty before but it didn't seem to work.  I must be missing something here as well. 

Start | Run | telnet <IP address> 110 should work as a test.  If this works and t-bird does not it really looks like a firewall is blocking t-bird.

Can the DHCP-server work flawlessly with a badly configured DNS-server?  

Yes, no and maybe.  The badly configured DNS may not be badly configured for DCHP.  If you use the IP address it should not even be looking at the DNS system to make the connection.

In Thunderbird my server name is configured by IP-address.  Should I try telnetting by name, would that make any difference?

IP address should work just fine.  That said an IP address pointing to a local LAN address (192.168.x.x) and one pointed to an external address do have a lot of differences in the route to host.  

Any hints?

[/quote]
&lt;blockquote&gt;[quote user=&quot;Jim Pow&quot;]Thx for the reply You seem to know stuff :)&lt;p&gt;I tried telnet with&amp;nbsp;putty before but it didn&#039;t&amp;nbsp;seem to work.&amp;nbsp; I must be missing something here as well.&amp;nbsp;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Start | Run | telnet &amp;lt;IP address&amp;gt; 110 should work as a test.&amp;nbsp; If this works and t-bird does not it really looks like a firewall is blocking t-bird. &lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Can&amp;nbsp;the DHCP-server work flawlessly with a badly configured DNS-server?&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Yes, no and maybe.&amp;nbsp; The badly configured DNS may not be badly configured for DCHP.&amp;nbsp; If you use the IP address it should not even be looking at the DNS system to make the connection. &lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;In Thunderbird&amp;nbsp;my server name is&amp;nbsp;configured by IP-address.&amp;nbsp; Should I try telnetting by name, would that make any difference?&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;IP address should work just fine.&amp;nbsp; That said an IP address pointing to a local LAN address (192.168.x.x) and one pointed to an external address do have a lot of differences in the route to host. &amp;nbsp; &lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Any hints?&lt;/p&gt;[/quote]&lt;/blockquote&gt;

Ok, I appreciate this.

 

It will take a while before I can try this on the system. 

If this still doesn't work next time I can try to back my problem up with some screens. 

&lt;P&gt;Ok, I appreciate this.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;It will take a while before I can try this on the system.&amp;nbsp; &lt;/P&gt; &lt;P&gt;If&amp;nbsp;this still&amp;nbsp;doesn&#039;t work next time&amp;nbsp;I can&amp;nbsp;try to&amp;nbsp;back my problem&amp;nbsp;up with some screens.&amp;nbsp;&lt;/P&gt;

Hi guys,

Finally found the time to work on the new server again.

Trying this:

(=dutch, means connection is being made to...) didn't do anything, it just stayed like this without a respond. 

same here...

This one below works:

 This screen here shows the firewall is set off and when it was still on I've unblocked connections to port 110, 24 ,143...

 

I have a few errors on some of the functions of the server, maybe someone knows if they have anything to do with the telnet problem.  I'm experiencing great difficulties in understanding them.  These come up when I push the 'Online Help' button, the original message is in Dutch.

 

Event ID 2886 — LDAP signing
Updated: July 1, 2009

Applies To: Windows Server 2008 R2


To enhance the security of directory servers, you can configure both Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS) to require signed Lightweight Directory Access Protocol (LDAP) binds.

Unsigned network traffic is susceptible to replay attacks, in which an intruder intercepts an authentication attempt and the issue of a ticket. The intruder can reuse the ticket to impersonate the legitimate user. In addition, unsigned network traffic is susceptible to man-in-the-middle attacks, in which an intruder captures packets between the client computer and the server, modifies the packets, and then forwards them to the server. When this behavior occurs on an LDAP server, an attacker can cause a server to make decisions that are based on forged requests from the LDAP client.

Consider enhancing the security of your domain controllers by configuring them to reject simple LDAP bind requests and other bind requests that do not include LDAP signing.

 

Event ID 4007 — DNS Server Active Directory Integration
Updated: November 13, 2007

Applies To: Windows Server 2008


You can configure the DNS Server service to use Active Directory Domain Services (AD DS) to store zone data. This makes it possible for the DNS server to rely on directory replication, which enhances security, reliability, and ease of administration.

 

I hope you can help because this stuff goes beyond my knowledge and it's going to take lots of time for me to solve this, if ever.

 thank you

&lt;P&gt;Hi guys,&lt;/P&gt; &lt;P&gt;Finally found the time to work on the new server again.&lt;/P&gt; &lt;P&gt;Trying this:&lt;/P&gt; &lt;P&gt;&lt;IMG src=&quot;http://www.ostendpowers.be/downloads/error.jpg&quot; mce_src=&quot;http://www.ostendpowers.be/downloads/error.jpg&quot;&gt;&lt;/P&gt; &lt;P&gt;(=dutch, means connection is being made to...) didn&#039;t do anything, it just stayed like this without a respond.&amp;nbsp; &lt;/P&gt; &lt;P&gt;&lt;IMG src=&quot;http://www.ostendpowers.be/downloads/error1.jpg&quot; mce_src=&quot;http://www.ostendpowers.be/downloads/error1.jpg&quot;&gt;&lt;/P&gt; &lt;P&gt;same here...&lt;/P&gt; &lt;P&gt;This one below&amp;nbsp;works:&lt;/P&gt; &lt;P&gt;&lt;IMG src=&quot;http://www.ostendpowers.be/downloads/error4.jpg&quot; mce_src=&quot;http://www.ostendpowers.be/downloads/error4.jpg&quot;&gt;&lt;/P&gt; &lt;P&gt;&amp;nbsp;This screen here shows the firewall is set off and when it was still on I&#039;ve unblocked connections to port 110, 24 ,143...&lt;/P&gt; &lt;P&gt;&lt;IMG src=&quot;http://www.ostendpowers.be/downloads/error2.jpg&quot; mce_src=&quot;http://www.ostendpowers.be/downloads/error2.jpg&quot;&gt;&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I have a few errors on some of the functions of the server, maybe someone knows if they have anything to do with the telnet problem.&amp;nbsp; I&#039;m experiencing great difficulties in understanding them.&amp;nbsp; These come up when I push the &#039;Online Help&#039; button, the original message is in Dutch.&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;Event ID 2886 &mdash; LDAP signing Updated: July 1, 2009&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;Applies To: Windows Server 2008 R2&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt; To enhance the security of directory servers, you can configure both Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS) to require signed Lightweight Directory Access Protocol (LDAP) binds.&lt;/P&gt; &lt;P&gt;Unsigned network traffic is susceptible to replay attacks, in which an intruder intercepts an authentication attempt and the issue of a ticket. The intruder can reuse the ticket to impersonate the legitimate user. In addition, unsigned network traffic is susceptible to man-in-the-middle attacks, in which an intruder captures packets between the client computer and the server, modifies the packets, and then forwards them to the server. When this behavior occurs on an LDAP server, an attacker can cause a server to make decisions that are based on forged requests from the LDAP client.&lt;/P&gt; &lt;P&gt;Consider enhancing the security of your domain controllers by configuring them to reject simple LDAP bind requests and other bind requests that do not include LDAP signing. &lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;Event ID 4007 &mdash; DNS Server Active Directory Integration Updated: November 13, 2007&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;Applies To: Windows Server 2008&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt; You can configure the DNS Server service to use Active Directory Domain Services (AD DS) to store zone data. This makes it possible for the DNS server to rely on directory replication, which enhances security, reliability, and ease of administration. &lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I hope you can help because this stuff goes beyond my knowledge and it&#039;s going to take lots of time for me to solve this, if ever.&lt;/P&gt; &lt;P&gt;&amp;nbsp;thank you&lt;/P&gt;

This should not be an Active Directory or LDAP issue, but something is obviously blocking access to port 110 on your server. There has been lots of changes in Server 2008 regarding networking, and even if the firewall is deactivated there could still be for instance IPsec rules that block ports. This Technet document gives additional information:

http://technet.microsoft.com/en-us/library/cc766312(WS.10).aspx 

/Rolf 

&lt;p&gt;This should not be an Active Directory or LDAP issue, but something is obviously blocking access to port 110 on your server. There has been lots of changes in Server 2008 regarding networking, and even if the firewall is deactivated there could still be for instance IPsec rules that block ports. This Technet document gives additional information:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://technet.microsoft.com/en-us/library/cc766312(WS.10).aspx&quot;&gt;http://technet.microsoft.com/en-us/library/cc766312(WS.10).aspx&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;/Rolf&amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft