Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Conduit ssl error

Updated: 13 Aug 2010 | 5 comments
prohol's picture
0 0 Votes
Login to vote

Welcome,

In BMF v 6.1.0.0 a have in log many conduit errors like:

5 Feb 2010 11:22:25 (ERROR:7868.6136): [12034] Network error occurred, SSL: error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol (35), check your network connection settings, check your proxy settings (if applicable), and check to ensure that port 443 (HTTPS) is open through any relevant firewalls.

We have exchange 2003 on cluster, and I only renew our ssl certificates on IIS (OWA) 2 days ago.

What are this errors mean? Some people calling, that his mailbox are work slower. This errors can to affect on mailbox (exchange) performence? How to fix this errors?

Discussion Filed Under:

Comments

Nate Brogan's picture
05
Feb
2010
0 Votes 0
Login to vote

This error means conduit had

This error means conduit had a temporary problem either downloading rules or reporting stats back to Symantec.  It does not affect message throughput.

Do you use a proxy?  (The error seems to indicate the Symantec server is not "talking" ssl, possibly caused by proxy behavior)
How often are the errors? (1 min, 15 min, 1 hour, etc apart)

prohol's picture
05
Feb
2010
0 Votes 0
Login to vote

We dont have proxy. These

We dont have proxy. These errors appears in minutes interval (few times per minutes). 

Nate Brogan's picture
05
Feb
2010
0 Votes 0
Login to vote

Can you include a a larger

Can you include a a larger sampling of your log. It is possible these are just times when the Symantec web sever went down temporarily for maintenance.

Mr.BadExample's picture
08
Feb
2010
0 Votes 0
Login to vote

Have you had a chance to

Have you had a chance to verify that you can connect out to the correct location over port 443?  This could be a network related issue, i.e. a firewall blocking the connection to the Symantec Brightmail backend servers.

If you do a test from the command/shell line this may help you can try:

On the server, at the prompt type:

telnet aztec.brightmail.com 443

If you get any error message you can't connect  that means that something is blocking this servers ability to connect over port 443 to aztec.brightmail.com. 

Seeing a blank screen means that a connection was established.

prohol's picture
12
Feb
2010
0 Votes 0
Login to vote

Thanks, this errors

Thanks, this errors disappear...we had problem with exchange. owa etc