Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

“451 Transaction failed. ERROR: Scan result uncertain…” appears when sending mails on InterScan Messaging Security Virtual Appliance (IMSVA)

    • Updated:
    • 21 Oct 2015
    • Product/Version:
    • InterScan Messaging Security Virtual Appliance 8.2
    • InterScan Messaging Security Virtual Appliance 8.5
    • InterScan Messaging Security Virtual Appliance 9.0
    • Platform:
    • N/A N/A
Summary

The following error message appears and mails are not delivered on IMSVA:

451 Transaction failed. ERROR: Scan result uncertain. (in reply to end of DATA command)

The log.imss file shows the following entry for the emails:

[ERROR] Failed to receive policy response from IP:5060

Details
Public

The issue occurs because the Policy Server cannot be queried.

Scenario 1: Policy Server is not started or has issues with handling requests

Do the following:

  1. Restart the Policy Server. Run the following command:

    /opt/trend/imss/script/S99POLICY restart

  2. Increase the Policy Server timeout by adjusting two values in the SQL configuration database and reloading the IMSS service.
    1. In the console of your IMSVA parent, run the following commands:

      /opt/trend/imss/PostgreSQL/bin/psql -U sa -d imss
      imss=#update tb_global_setting set value='120' where name='send_timeout_secs';
      imss=#update tb_global_setting set value='120' where name='recv_timeout_secs';
      imss=#\q

      The result should look like this:

      /opt/trend/imss/PostgreSQL/bin/psql -U sa -d imss
      imss=#update tb_global_setting set value='120' where name='send_timeout_secs'; UPDATE 1
      imss=#update tb_global_setting set value='120' where name='recv_timeout_secs'; UPDATE 1
      imss=#\q

    2. Restart the IMSS Services by running the following commands:

      cd /opt/trend/imss/script
      /S99IMSS restart

Scenario 2: LDAP server is configured

  • Check if the LDAP server has network connection issues, for example, if the bandwidth to the LDAP server is very small or if the firewall in the middle keeps disconnecting from IMSVA.
    If the LDAP server type is Microsoft Active Directory, use port 3268 (Global Catalogue) instead of 389 (LDAP).
  • If you are not using IMSVA policies with LDAP users/groups, disable the Policy Server:
     
    This will not impact the EUQ and LDAP recipient check functionality.
    1. Back up the /opt/trend/imss/config/imss.ini file.
    2. Under the [policy_server] section, add the following line:

      disableldap=yes

       
      If [policy_server] section does not exist, add it at the bottom of the file including the parameter.

      Example:

      [policy_server]
      disableldap=yes

    3. Restart the IMSS Services by running the following commands:

      cd /opt/trend/imss/script
      /S99IMSS restart

Premium
Internal
Rating:
Category:
Troubleshoot
Solution Id:
1098830
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.