First off, this is a lab environment - no internet connection.
EXCH-A01: W2K8R2x64-SP1, joined to domain, 10.x.x.x network, DNS is AD Integrated 10.x.x.101
EDGE-A01: W2K8R2x64-SP1, NOT joined to domain but FQDN set to be same domain as EXCH-A01, 200.x.x.x network, DNS is NOT AD integrated 200.x.x.201
EXCH-A01 can nslookup and ping EDGE-A01 by FQDN.
EDGE-A01 can NOT nslookup BUT it CAN pin EXCH-A01 by FQDN - guessing this is part of the issue but can't find why.
Created the EDGE-A01 and EXCH-A01 sync file and synching is working. If I change settings on the hub for send connectors, they are reflected on the edge.
Mail sent from user inside the domain to xxx@yahoo.com gets stuck in the outgoing queue on the EXCH-A01(hub) server and never gets to the EDGE-A01.
As a test, changed network configuration for EDGE-A01 and moved it onto the 10.x.x.x network; recreated the sync and tried the email test again. This time the email left the hub and sat in the queue on the edge - which is what I expected. Eventually, the edge gaveup trying to send the email and sent back an undeliverable message.
SO questions/issues:
What DNS entries need to be on the DNS that is configured inside the DMZ. Currently I have just the 200.x.x.x machines' A records.
Manually created an A record on the primary DNS (AD integrated zone) for the EDGE-A01 200.x.x.x so that EXCH-A01 can nslookup and ping the edge by FQDN.
I found 1 reference on technet that says the EDGE-A01 must be dual NICd - this makes no sense as it defeats the purpose of having it in the DMZ (at least in my opinion).
The error in the queue for EXCH-A01: "451 5.7.3 Cannot achieve Exchange Server authentication." - guessing this has part to do with it but searching all points to firewall/ASA issues. EVERY firewall in the domain is turned off. ASA is configured to allow any/any right now.
I've been searching here and elsewhere online and found every setup/installation guide. I've deleted and rebuilt the EDGE-A01 3 times. Been fighting this for 2 weeks and really need to figure this out as the next step will be harder - how to simulate the internet in this lab so that the mail actually looks like it goes out and comes back.
Appreciate any help/links/pointers anyone can provide.