<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.tetrain.com/index.php?action=history&amp;feed=atom&amp;title=NFC_Troubleshooting_Document.</id>
	<title>NFC Troubleshooting Document. - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.tetrain.com/index.php?action=history&amp;feed=atom&amp;title=NFC_Troubleshooting_Document."/>
	<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=NFC_Troubleshooting_Document.&amp;action=history"/>
	<updated>2026-07-27T11:10:49Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=NFC_Troubleshooting_Document.&amp;diff=4309&amp;oldid=prev</id>
		<title>Admin: Auto-created from uploaded PDF text extraction</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=NFC_Troubleshooting_Document.&amp;diff=4309&amp;oldid=prev"/>
		<updated>2026-07-26T16:27:10Z</updated>

		<summary type="html">&lt;p&gt;Auto-created from uploaded PDF text extraction&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;Auto-generated from the uploaded PDF [[:File:NFC_Troubleshooting_Document..pdf|NFC_Troubleshooting_Document..pdf]]. This is an extracted-text rendering for searchability; see the original PDF for exact formatting, diagrams, tables, and images.&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&lt;br /&gt;
Index:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Table of Contents&lt;br /&gt;
1. How to add DAE IP’s in MTA servers. ..............................................................................................2&lt;br /&gt;
2. How to add DAE domains in MTA servers........................................................................................3&lt;br /&gt;
3. How to Find differed mails in MTA servers. .....................................................................................3&lt;br /&gt;
4. If Mails are in Deferred mode we need to flush manually by using below command. .......................4&lt;br /&gt;
5. CLUSTER CHECKING ........................................................................................................................5&lt;br /&gt;
6. We should check that shared storage(/opt) mounted or not in both mbox servers...........................6&lt;br /&gt;
7. Mails Trace out ..............................................................................................................................7&lt;br /&gt;
8. Mail sent but mail delivery failed ....................................................................................................8&lt;br /&gt;
9. Email Log Analysis ..........................................................................................................................8&lt;br /&gt;
10. Attachment restriction is ON/OFF .................................................................................................9&lt;br /&gt;
11. change Mail Routing from UUCP to Anunet and Vice Versa.......................................................... 10&lt;br /&gt;
12. USER PERMISSIONS FOR OUTSIDE MAILS WITH AND WITHOUT ATTACHMENTS ....................... 11&lt;br /&gt;
13. User Transfer From NFC to ZC/KOTA or vice versa ....................................................................... 13&lt;br /&gt;
14. Restrict Users to send a mail outside (Gmail, yahoo) ................................................................... 14&lt;br /&gt;
15. Gal sync accounts. ...................................................................................................................... 16&lt;br /&gt;
16. User Unable to send/receive Mails ............................................................................................. 18&lt;br /&gt;
17. Drbd is checking in both serves in KOTA and ZC locations. ........................................................... 19&lt;br /&gt;
18. Zimbra email flow: ..................................................................................................................... 21&lt;br /&gt;
19. To check all services status at all three location status, start &amp;amp; stop check below ......................... 22&lt;br /&gt;
20. Check HAProxy 1 &amp;amp;HAProxy 2 status, we have to login 10.172.98.207&amp;amp; 208................................. 23&lt;br /&gt;
21. All port’s &amp;amp; bridges from HYD KVM BM ....................................................................................... 24&lt;br /&gt;
22. To enable SSL certificate for mails……………………………………………………………………………………………………30&lt;br /&gt;
&lt;br /&gt;
23. To enable Rocket Chat SSL certificate for mail&amp;#039;s………………………………………………………………………………31&lt;br /&gt;
&lt;br /&gt;
24. SOP for Antivirus updation on Email Systems…………………………………………………………………………………33&lt;br /&gt;
&lt;br /&gt;
25. Change Mail Routing from UUCP to Anunet and Vice Versa …………………………………………….35&lt;br /&gt;
&lt;br /&gt;
26. Account Setup Status of User Accounts Admin Console…………………………….37&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                                                                  1|Page&lt;br /&gt;
&lt;br /&gt;
1. How to add DAE IP’s in MTA servers.&lt;br /&gt;
We need to login to both MTA servers and follow the below process.&lt;br /&gt;
&lt;br /&gt;
# cd /opt/zimbra/common/conf&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2. How to add DAE domains in MTA servers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We need to login to both MTA servers and follow the below process.&lt;br /&gt;
&lt;br /&gt;
# cd /opt/zimbra/common/conf&lt;br /&gt;
&lt;br /&gt;
# vi local_domains&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                     2|Page&lt;br /&gt;
&lt;br /&gt;
3. How to Find differed mails in MTA servers .&lt;br /&gt;
          MTA 1&lt;br /&gt;
          MTA 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We need to login to both MTA servers and follow the below process.&lt;br /&gt;
&lt;br /&gt;
# cd /var/spool/postfix-2/deferred&lt;br /&gt;
&lt;br /&gt;
# ls&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                     3|Page&lt;br /&gt;
&lt;br /&gt;
4. If Mails are in Deferred mode we need to flush manually by using below&lt;br /&gt;
command.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# /usr/sbin/postqueue-c /etc/postfix-2/ -f&lt;br /&gt;
&lt;br /&gt;
# /opt/zimbra/common/sbin/postqueue -f&lt;br /&gt;
&lt;br /&gt;
# /usr/sbin/postqueue -f&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
5. CLUSTER CHECKING&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    1.   Login to mailbox servers and check cluster status.&lt;br /&gt;
    2.   Both Nodes should be online otherwise we will get problem.&lt;br /&gt;
    3.   Please find the below process&lt;br /&gt;
    4.   How to check the cluster status and stand by and unstand by the nodes?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                  4|Page&lt;br /&gt;
&lt;br /&gt;
# pcs status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
       In above image displays both nodes show Online.&lt;br /&gt;
       We can find the ip and zimbra running on which node .&lt;br /&gt;
       If only one node is online, it may cause the problem when online machine is down. Production&lt;br /&gt;
        will stop.&lt;br /&gt;
       Because of that reason both nodes should be online.&lt;br /&gt;
       Please find the below image.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# pcs status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                           5|Page&lt;br /&gt;
&lt;br /&gt;
         If we want move the cluster services manually follow the below commands.&lt;br /&gt;
&lt;br /&gt;
    # pcs node standby mbox2-hyd.nfc.gov.in (It means mbox2 should be going to offline)&lt;br /&gt;
&lt;br /&gt;
    # pcs node unstandby mbox2-hyd.nfc.gov.in (It means mbox2 should be going to online)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    6. We should check that shared storage(/opt) mounted or not in both mbox&lt;br /&gt;
    servers.&lt;br /&gt;
&lt;br /&gt;
         Please find the below command and images.&lt;br /&gt;
&lt;br /&gt;
# df –h&lt;br /&gt;
&lt;br /&gt;
         /dev/mapper/vg_gfs2-lv_gfs2 7.0T 4.2T 2.9T 60% /opt (shared storage)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                           6|Page&lt;br /&gt;
&lt;br /&gt;
7. Mails Trace out&lt;br /&gt;
       We need to login to both MTA servers&lt;br /&gt;
       After logging switch to zimbra user and run below commands.&lt;br /&gt;
       Please find the below image.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# su – zimbra&lt;br /&gt;
&lt;br /&gt;
 # ./libexec/zmmsgtrace -s sender@nfc.gov.in -r receiver@nfc.gov.in /var/log/zimbra.log-20240511.gz&lt;br /&gt;
(path)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
8. Mail sent but mail delivery failed&lt;br /&gt;
1) First we need to log in MTA SERVERS as a root user.&lt;br /&gt;
&lt;br /&gt;
2)Switch to zimbra user&lt;br /&gt;
&lt;br /&gt;
a) su – zimbra&lt;br /&gt;
&lt;br /&gt;
3) Then there is a reason for delivery failed.&lt;br /&gt;
&lt;br /&gt;
i) Mail in mailq.&lt;br /&gt;
&lt;br /&gt;
 ii) differed: blocked in Imsva level&lt;br /&gt;
&lt;br /&gt;
 iii) Bounce back: If we didn’t get any bounce back we can trace out the mail by the following command.&lt;br /&gt;
&lt;br /&gt;
                                                                                            7|Page&lt;br /&gt;
&lt;br /&gt;
ii) We require both sender and reciver address&lt;br /&gt;
&lt;br /&gt;
# ./libexec/zmmsgtrace -s sender@mail.com -r reciver@mail.com.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
9. Email Log Analysis&lt;br /&gt;
                    Important logs.&lt;br /&gt;
&lt;br /&gt;
              a.   /var/log/maillog&lt;br /&gt;
              b.   /var/log/zimbra.log&lt;br /&gt;
              c.   /opt/zimbra/log/mailbox.log&lt;br /&gt;
              d.   /opt/zimbra/log/audit.log&lt;br /&gt;
&lt;br /&gt;
#     /var/log/maillog : In this log we can find delivery of mails.&lt;br /&gt;
&lt;br /&gt;
# /var/log/zimbra.log: In this log we can find delivery of mails and also amavis everything.&lt;br /&gt;
&lt;br /&gt;
# /opt/zimbra/log/mailbox.log: In this log we can find user what is mail id Orgin IP and type of&lt;br /&gt;
webclient.&lt;br /&gt;
&lt;br /&gt;
# /opt/zimbra/log/audit.log: In this log we can find user what is mail id Orgin IP and also authentications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
    # tail –f /var/log/maillog : For continous logs&lt;br /&gt;
&lt;br /&gt;
 # less /var/log/maillog | grepuser@nfc.gov.in : we can find mail deliver r not.&lt;br /&gt;
&lt;br /&gt;
# cat /opt/zimbra/log/audit.log | grepuser@nfc.gov.in : to find a user login time and IP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
10. Attachment restriction is ON/OFF&lt;br /&gt;
      1. First we need to login to MTA Servers of Hyderabad (mta1 and mta2).&lt;br /&gt;
      2. Login through putty.&lt;br /&gt;
      3. Please follow the below commands&lt;br /&gt;
         a) cd /opt/zimbra/common/conf&lt;br /&gt;
         b) In this path two files&lt;br /&gt;
         i) group1_transport and group2_transport&lt;br /&gt;
           ii) group1_transport = this file has some users they have attachment facility&lt;br /&gt;
         iii) If we want to give permission to any user to send attachment outside add in this file. After&lt;br /&gt;
         adding need to run following command.&lt;br /&gt;
          iv) postmap /opt/zimbra/common/conf/group1_transport .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                                 8|Page&lt;br /&gt;
&lt;br /&gt;
   Please follow the below commands&lt;br /&gt;
&lt;br /&gt;
a) cd /opt/zimbra/common/conf&lt;br /&gt;
&lt;br /&gt;
group2_transport&lt;br /&gt;
&lt;br /&gt;
i) group2_transport = this file has some users they have without attachment facility.&lt;br /&gt;
ii) If we want to give permission outside to any user without attachment add in this file after&lt;br /&gt;
adding need to run following command.&lt;br /&gt;
iii) postmap /opt/zimbra/common/conf/group2_transport&lt;br /&gt;
iv) Please find the below image.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                        9|Page&lt;br /&gt;
&lt;br /&gt;
11. change Mail Routing from UUCP to Anunet and Vice Versa&lt;br /&gt;
          Become zimbra user after login to the both Hyderabad MTA servers (98.201 and 98.204).&lt;br /&gt;
          Open /opt/zimbra/common/conf/transportfile&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Comment all the lines containing 172.16.29.100 (Anunet SMTP server) and save the file.&lt;br /&gt;
 run postmap /opt/zimbra/common/conf/transportfile.&lt;br /&gt;
 To revert back to anunet gateway repeat 3rd step uncommenting and run step 4.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                           10 | P a g e&lt;br /&gt;
&lt;br /&gt;
   12. USER PERMISSIONS FOR OUTSIDE MAILS WITH AND WITHOUT ATTACHMENTS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                   1. After creation of email and archive accounts we need to give outside mails&lt;br /&gt;
                      permission.&lt;br /&gt;
                   2. Generally we have “2” MTA Servers in our system we need to add user in that&lt;br /&gt;
                      servers.&lt;br /&gt;
                   3. We have “2” groups in each MTA Servers.&lt;br /&gt;
                   4. group1_transport ( In this group of users able to send attachments outside with&lt;br /&gt;
                      25MB only).&lt;br /&gt;
                   5. group2_transport (In this group of users able to send only mails outside without&lt;br /&gt;
                      attachments).&lt;br /&gt;
                   6. Login to “MTA SERVERS “as a Zimbra user and execute the following commands&lt;br /&gt;
                      and find the below images.&lt;br /&gt;
                   7. After adding mail id in groups we need to run postmap command which is given&lt;br /&gt;
                      below.&lt;br /&gt;
&lt;br /&gt;
# su – zimbra&lt;br /&gt;
&lt;br /&gt;
$ cd /opt/zimbra/common/conf/&lt;br /&gt;
&lt;br /&gt;
$ vi group1_transport&lt;br /&gt;
&lt;br /&gt;
$ postmap /opt/zimbra/common/conf/group1_transport&lt;br /&gt;
&lt;br /&gt;
$ vi group1_2ransport&lt;br /&gt;
&lt;br /&gt;
$ postmap /opt/zimbra/common/conf/group2_transport&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                          11 | P a g e&lt;br /&gt;
&lt;br /&gt;
$ postmap /opt/zimbra/common/conf/group1_transport&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                     12 | P a g e&lt;br /&gt;
&lt;br /&gt;
13. User Transfer From NFC to ZC/KOTA or vice versa&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 First Login into admin panel&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Search a user we want to transfer account from one location to another.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                            13 | P a g e&lt;br /&gt;
&lt;br /&gt;
 Select Move mailbox.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 The selected user previously in Hyderabad server as shown below.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 We can move to Kota or ZC locations as shown below image and Vice-versa archive mail id also need&lt;br /&gt;
  to move.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Save it&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
14. Restrict Users to send a mail outside (Gmail, yahoo)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Login to MTA Servers and switch to zimbra user&lt;br /&gt;
 Run following commands.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                       14 | P a g e&lt;br /&gt;
&lt;br /&gt;
# su – zimbra&lt;br /&gt;
&lt;br /&gt;
# cd /opt/zimbra/common/conf&lt;br /&gt;
&lt;br /&gt;
# cat restricted_senders&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                               15 | P a g e&lt;br /&gt;
&lt;br /&gt;
15. Gal sync accounts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Please find the gal sync accounts depends on location&lt;br /&gt;
 If user’s mailbox takes more time for loading, please check different location gal sync account&lt;br /&gt;
  mounted.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
galsync.0xcn_3eu4z@nfc.gov.in - Kota archive&lt;br /&gt;
&lt;br /&gt;
galsync.9ljcthrp@nfc.gov.in     - Hyd archive&lt;br /&gt;
&lt;br /&gt;
galsync.osnphefhw7@nfc.gov.in - ZC archive&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
galsync.aewzjywpp@nfc.gov.in      - ZC mailbox&lt;br /&gt;
&lt;br /&gt;
galsync.qq7du2_vc@nfc.gov.in      - Kota mailbox&lt;br /&gt;
&lt;br /&gt;
galsync.yxn8jp0m@nfc.gov.in      - Hyd mailbox&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
     Please find the below commands to check and remove.&lt;br /&gt;
     Login to mailbox server and switch to zimbra user.&lt;br /&gt;
&lt;br /&gt;
        # su – zimbra&lt;br /&gt;
        # zmmailbox -z -m vsai@nfc.gov.in gaf (to get the user mount information)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                            16 | P a g e&lt;br /&gt;
&lt;br /&gt;
    In Above image if any different gal sync account mount we can remove by using below&lt;br /&gt;
     command.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 # zmmailbox -z -m vsai@nfc.gov.in (hyd-user)df/galsync.0xcn_3eu4z_InternalGAL( kota-archive mount&lt;br /&gt;
point)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                      17 | P a g e&lt;br /&gt;
&lt;br /&gt;
16. User Unable to send/receive Mails&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    User unable send/receive mails.&lt;br /&gt;
    Please check the quota of user.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                        18 | P a g e&lt;br /&gt;
&lt;br /&gt;
17. Drbd is checking in both serves in KOTA and ZC locations .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
           We need to check every day weather data sync or not in between two mail box servers.&lt;br /&gt;
           If both are not sync means data is not replicating into secondary.&lt;br /&gt;
           mbox 1 is primary and mbox2 is secondary both should be up to date.&lt;br /&gt;
           If mbox1 down all service shifted to mbox 2 that time data will not be lost&lt;br /&gt;
           If both are not up to date mbox1 down all service shifted tombox 2 that time data will&lt;br /&gt;
            be lost.&lt;br /&gt;
           So before doing any changes need to check&lt;br /&gt;
&lt;br /&gt;
#drbdadm status&lt;br /&gt;
&lt;br /&gt;
# drbdadm connect drbd1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    Mbox1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                       19 | P a g e&lt;br /&gt;
&lt;br /&gt;
    Mbox2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Zcmbox1&lt;br /&gt;
&lt;br /&gt;
#drbdadm status&lt;br /&gt;
&lt;br /&gt;
# drbdadm connect drbd1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Zcmbox2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#drbdadm status&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                          20 | P a g e&lt;br /&gt;
&lt;br /&gt;
18. Zimbra email flow:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                         21 | P a g e&lt;br /&gt;
&lt;br /&gt;
19. To check all services status at all three location status, start &amp;amp; stop check&lt;br /&gt;
below&lt;br /&gt;
    Login as a root user then swith to zimbra user then please follow the below commands:&lt;br /&gt;
     # zmcontrol status&lt;br /&gt;
     # zmcontrol start&lt;br /&gt;
     # zmcontrol restart&lt;br /&gt;
     # zmcontrol stop&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
10.172.98.204 &amp;amp; 201 [MTA 1 &amp;amp; 2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
10.172.98.203 &amp;amp; 206 [Ldap 1 &amp;amp; 2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
10.172.98.209 archive server&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                       22 | P a g e&lt;br /&gt;
&lt;br /&gt;
Need to verify with below commands:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Service Status         Services Start            Services Restart      Services Stop&lt;br /&gt;
zmcontrol status       zmcontrol start           zmcontrol restart     zmcontrol stop&lt;br /&gt;
to check all           If some services are      If all services are   If we need to stop the&lt;br /&gt;
services are           not running or            not running we        services, we have to&lt;br /&gt;
running or not         stopped, we have to       have to restart       use above command&lt;br /&gt;
                       use above command         the services using&lt;br /&gt;
                                                 above command&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
20. Check HAProxy 1 &amp;amp;HAProxy 2 status, we have to login 10.172.98.207&amp;amp; 208&lt;br /&gt;
#systemctl status haproxy (to check the status of the service)&lt;br /&gt;
&lt;br /&gt;
#systemctl start haproxy (to start the service if it is inactive)&lt;br /&gt;
&lt;br /&gt;
#systemctl stop haproxy (to stop the running service)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                                23 | P a g e&lt;br /&gt;
&lt;br /&gt;
21. All port’s &amp;amp; bridges from HYD KVM BM&lt;br /&gt;
HYD BM KVM 1 IP: [10.172.98.199:9090]&lt;br /&gt;
bridge0 &amp;amp; bridge1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
bridge0 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                           24 | P a g e&lt;br /&gt;
&lt;br /&gt;
bridge1 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
HYD BM KVM2 IP: [10.172.98.198:9090]&lt;br /&gt;
Brige0 &amp;amp; bridge1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                       25 | P a g e&lt;br /&gt;
&lt;br /&gt;
Bridge0 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Bridge1 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                26 | P a g e&lt;br /&gt;
&lt;br /&gt;
HYD BM Archive : IP [10.172.98.200:9090]&lt;br /&gt;
Bridge0 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Bridge0 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                           27 | P a g e&lt;br /&gt;
&lt;br /&gt;
HYD Internal KSMG Anunet: IP [10.172.98.194:9090]&lt;br /&gt;
Bridge0 &amp;amp; bridge1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Bridge0 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                    28 | P a g e&lt;br /&gt;
&lt;br /&gt;
Bridge1 ports&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                29 | P a g e&lt;br /&gt;
&lt;br /&gt;
22. To enable SSL certificate for mails&lt;br /&gt;
      We have to login HAProxy 1 &amp;amp; 2 in all 3 locations, IP’s mentioned below&lt;br /&gt;
      HYD HAProxy 1 &amp;amp; 2 [10.172.98.207 &amp;amp; 208]&lt;br /&gt;
      KOTA HAProxy 1 &amp;amp; 2 [10.174.98.77 &amp;amp; 78]&lt;br /&gt;
      ZC HAProxy 1 &amp;amp; 2 [10.173.120.47 &amp;amp; 48]&lt;br /&gt;
Commands to enter the path&lt;br /&gt;
&lt;br /&gt;
# cd /etc/haproxy/certs/&lt;br /&gt;
# ls&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
      For Previous file we are taking backup file name bundle.pem renamed as&lt;br /&gt;
       bundle_old.pem&lt;br /&gt;
      We combined 3 SSL files into a new file named as bundle-new-4.pem&lt;br /&gt;
# cat privatekey.key EndEntity_wc.nfc.gov.in.cer &amp;#039;CA_emSign SSL CA - G1.cer&amp;#039; &amp;gt; bundle-new-&lt;br /&gt;
4.pem&lt;br /&gt;
# mv bundle-new-4.pem bundle.pem        (we renamed bundle-new-4.pem as bundle.pem)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
      After making changes we need to restart the HAProxy services&lt;br /&gt;
      After restart check the status commands are mentioned below&lt;br /&gt;
# systemctl restart haproxy&lt;br /&gt;
# systemctl status haproxy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                   30 | P a g e&lt;br /&gt;
&lt;br /&gt;
Chat SSL certificate:&lt;br /&gt;
&lt;br /&gt;
IP: 10.172.98.228&lt;br /&gt;
&lt;br /&gt;
# cd /etc/nginx/&lt;br /&gt;
&lt;br /&gt;
# ls&lt;br /&gt;
&lt;br /&gt;
# ll&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We have taken backup old files as certificate_old.crt certificate_old.key&lt;br /&gt;
&lt;br /&gt;
# mv certificate.crt certificate_old.crt&lt;br /&gt;
&lt;br /&gt;
# mv certificate.key certificate_old.key&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After adding new ssl certificate file, We need to restart the service&lt;br /&gt;
&lt;br /&gt;
# systemclt restart nginx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                            31 | P a g e&lt;br /&gt;
&lt;br /&gt;
SOP for Antivirus updation on Email Systems:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   1. Download latest updates from website using the following links&lt;br /&gt;
&lt;br /&gt;
       https://www.qnap.com/en-as/how-to/faq/article/how-to-update-clamav-virus-database-&lt;br /&gt;
       manually&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   2. Process to update ClamAV &amp;amp; Process for placing the files on 10.172.98.227&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
       # cd /clamav_backup/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                    32 | P a g e&lt;br /&gt;
&lt;br /&gt;
   #ls&lt;br /&gt;
   bytecode.cvd daily.cvd main.cvd&lt;br /&gt;
   #rm -rf bytecode.cvd daily.cvd main.cvd&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
            We will take backup for old updated files in clamav_backup folder&lt;br /&gt;
&lt;br /&gt;
       # cd /var/www/html/clamavdb&lt;br /&gt;
       # mv bytecode.cvd daily.cvd main.cvd /clamav_backup&lt;br /&gt;
&lt;br /&gt;
            After taking backup from /var/www/html/clamavdb folder to clamav_backup folder&lt;br /&gt;
&lt;br /&gt;
3. Procedure for Verify and copy the downloaded files from Internet to NFCNet :&lt;br /&gt;
        After downloading from internet we will place those files in antivirus server with the&lt;br /&gt;
          help of hardisk&lt;br /&gt;
        Through Winscp We will copy the files after downloading from internet&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   Winscp:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
       # cd /var/www/html/clamavdb&lt;br /&gt;
       # ls&lt;br /&gt;
   bytecode-334.cdiff bytecode.cvd daily-27184.cdiff daily.cvd dns.txt main-62.cdiff main.cvd&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                       33 | P a g e&lt;br /&gt;
&lt;br /&gt;
4. Verification procedure:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    # /opt/zimbra/common/bin/freshclam --version --config-file=/opt/zimbra/conf/freshclam.conf&lt;br /&gt;
&lt;br /&gt;
   Result:&lt;br /&gt;
   ClamAV 1.0.1/27313/Fri Jun 21 13:58:08 2024&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                   34 | P a g e&lt;br /&gt;
&lt;br /&gt;
Change Mail Routing from UUCP to Anunet and Vice Versa&lt;br /&gt;
             Switch to zimbra user after login to the both Hyderabad MTA servers, IP’s mentioned below&lt;br /&gt;
             IP’s : (10.172.98.201 and 10.172.98.204)&lt;br /&gt;
             Open #Cd /opt/zimbra/common/conf/transportfile&lt;br /&gt;
             # ls&lt;br /&gt;
             # Cat transportfile&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To change the routing from anunet to internet IMSVA&lt;br /&gt;
&lt;br /&gt;
# vi transportfile&lt;br /&gt;
&lt;br /&gt;
After opening we need to give # comment for domains in both mta1 &amp;amp; mta2 as shown below image&lt;br /&gt;
&lt;br /&gt;
After giving # comment we need to run postmap, command given below&lt;br /&gt;
&lt;br /&gt;
# postmap transportfile (in both MTA’s)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                           35 | P a g e&lt;br /&gt;
&lt;br /&gt;
After running postmap in both MTA’s mails go through internet IMSVA&lt;br /&gt;
&lt;br /&gt;
To revert back to anunet gateway repeat the step uncommenting and run #postmap transportfile in&lt;br /&gt;
both MTA’s&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                       36 | P a g e&lt;br /&gt;
&lt;br /&gt;
Account Setup Status of User Accounts Admin Console:&lt;br /&gt;
Active: Mail account can open and operate&lt;br /&gt;
&lt;br /&gt;
Closed: Mail account can’t be opened, mails won’t be received and can’t be sent by end user.&lt;br /&gt;
&lt;br /&gt;
Locked: Mail account will can’t open mails can receive can send by end user.&lt;br /&gt;
&lt;br /&gt;
Pending: Mail account can’t be opened, mails won’t be received and can’t be sent by end user.&lt;br /&gt;
Maintenance: Mail account will can’t open mails can receive can send by end user.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please find the below step’s:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1. Active: Active Normal state for mailbox account. Mail is delivered and users can log in to the client&lt;br /&gt;
interface. The account is fully active and operational. The user can log in, send, and receive&lt;br /&gt;
emails without there restrictions.&lt;br /&gt;
&lt;br /&gt;
2. Closed: When a domain status is marked as closed, Login for accounts on the domain is disabled and&lt;br /&gt;
messages are bounced The user cannot log in or access the account.&lt;br /&gt;
&lt;br /&gt;
3. Locked: The account is locked. The user cannot log in, but incoming emails are still accepted&lt;br /&gt;
and delivered to the mailbox, Used as a temporary measure when an account needs to be&lt;br /&gt;
suspended without rejecting incoming emails, such as during an investigation or security&lt;br /&gt;
concern.&lt;br /&gt;
&lt;br /&gt;
4. Pending: The account is pending activation. It is not yet active, and the user cannot log in or&lt;br /&gt;
use the account. Used for accounts that have been created but are awaiting some form of&lt;br /&gt;
approval or activation process.&lt;br /&gt;
&lt;br /&gt;
5. Maintenance: The account is in maintenance mode. The user cannot log in, and incoming&lt;br /&gt;
emails will receive. Used when an account needs to be temporarily disabled for maintenance&lt;br /&gt;
purposes, such as data migration or troubleshooting.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                                                               37 | P a g e&lt;br /&gt;
&lt;br /&gt;
Please find the image below for Maintenance mode:&lt;br /&gt;
&lt;br /&gt;
This account is currently in maintenance mode.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                    38 | P a g e&lt;br /&gt;
&lt;br /&gt;
                                           BRIEFCASE SHARE FOLDER&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Briefcase is used to share a document/files to anyone of the user.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
     1.   Please login to mail your account.&lt;br /&gt;
     2.   Go to Briefcase and select folder.&lt;br /&gt;
     3.   Under briefcase we have created one folder nfc_highlights.&lt;br /&gt;
     4.   Right click on that folder.&lt;br /&gt;
     5.   Please find the below images.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                             39 | P a g e&lt;br /&gt;
&lt;br /&gt;
 Upload a document.&lt;br /&gt;
 Please find the below image.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    Upload a document under nfc_highlights folder.&lt;br /&gt;
    Please find below image.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                      40 | P a g e&lt;br /&gt;
&lt;br /&gt;
 Right click on nfc_highlights folder.&lt;br /&gt;
 Share folder with view or editable permissions.&lt;br /&gt;
 Please find below image.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                                    41 | P a g e&lt;br /&gt;
&lt;br /&gt;
42 | P a g e&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>