Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Mail Security for MSE problem with clustering

Updated: 23 May 2010 | 2 comments
mon_raralio's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Here's the scenario:
MS cluster with MS exchange and SMSMSE (Symantec Mail Security for Microsoft Exchange).
They're having problems with the Exchange because SMSMSE is in a stopping state. There is nothing in the logs that says otherwise except for an error in clustering (error 1460).
After checking on Symantec Knowledge base, I found out that it has something to do with the timing. For clustered environment, it is not advisable to make SMSMSE dependent upon another service. I think the current setup has the SMSMSE is dependent on another service since forcing the Symantec service to stop is-as the other guy said-would be a tedious process and is not an option. i.e. it would make things worse. Anyway, we just waited and for the service to stop and that did it.

I sent them this link: http://service1.symantec.com/support/ent-gate.nsf/...
for added measures.

Then I also found this while Googleing on the probable causes for the clustering side...
"
Problem:

The IIS, SMTP, POP3 and WWW services crash frequently on the Exchange with Symantec Antivirus servers and they took Exchange down. This happens with a frequency of once or twice an hour - or maybe more.

Resolution:

This issue is caused due to the Symantec Brightmail 5. The recommended workaround is to modify brightmail to no longer use the rulesets that are causing the issue.

Please Call Symantec to resolve this issue. Here is what they will probably tell you - to modify the bmiconfig.xml file.

To modify bmiconfig.xml to work around the issue:

Open the services menu by going to Start -> Run and typing services.msc
Stop the Symantec Mail security for Microsoft exchange service, and the Symantec Mail security spam statistics service, if they are started
Open :\Program iles\Symantec\SMSMSE\5.0\Server\SpamPrevention\bmiconfig.xml in a text editor such as notepad
Go to the File menu, choose save as, and save the file as bmiconfig.old
Delete the following 5 strings:
header_regex
body_regex
lang_header_regex
lang_body_regex
bodysig

Once those entries are deleted, go to the File menu, and choose save as, save the file as bmiconfig.xml

Restart the Symantec mail security for Microsoft exchange service; it is not necessary to restart the Spam statistics service

- An easier way is to save the bmiconfig.xml to your Desktop first. Edit it as per the instruction above. THEN stop the Symantec Services, Rename the bmiconfig.xml file and Copy the edited file back to it's original folder. THEN restart the Symantec AV Service(s).
"
The question is would this also be a feasible solution next time it happens?

discussion Filed Under:

Comments

TSE-JDavis's picture
27
Oct
2009
1 Vote +1
Login to vote

Doubtful

One thing to keep in mind is that you do not need to install Mail Security as cluster aware, it will function perfectly without it. The solution for Brightmail would not be applicable to Mail Security since they are such different products.

If this only happened once its possible it was an isolated issue. If it happens a lot you would want to consider a reinstall.

mon_raralio's picture
13
Nov
2009
1 Vote +1
Login to vote

Thanks for the reply. The

Thanks for the reply. The company have moved on to SBG 8 appliance since then.
I'm just not sure how the appliance locates the LDAP if it were clustered or the exchange server. I'm still learning what MX is all about.

“Your most unhappy customers are your greatest source of learning.”