Symantec Messaging Gateway (SMG) may defer connections from remote MTAs following a TLS negotiation failure. In some cases, if secure TLS communication cannot be negotiated, the sending mail server will immediately attempt a reconnect to deliver the message in plain text. In some cases, the Connection Classification feature in SMG This appears to be caused by incorrect handling by remote MTA of following:
Some mail servers will immediately retry sending a message in plain text if the negotiation of secure delivery via SMTP TLS fails. When the Connection Classification feature in Messaging Gateway is enabled this immediate redelivery attempt will trigger the "Reconnect Timeout" limit and cause the connection attempt to be deferred. If the sending mail server again attempts to deliver the message with TLS and fails, the fast retry will again be deferred by Connection Classification.
Based on data gathered so far this issue should be resolved on sending MTA side. Following are some suggestions on how this issue can be resolved on remote MTA side:
Here is the list of possible workarounds that can be evaluated for implementation on SMG side to restore the connectivity:
Please note: