Skip to main content
Nur
Staff
Staff
August 13, 2022

Troubleshooting Tip: FortiAnalyzer stops sending a report via Email

  • August 13, 2022
  • 0 replies
  • 2712 views
Description This article describes when the FortiAnalyzer can sniffer or ping the Email server, and still could not receive a report.
Scope The issue focus from the FortiAnalyzer site as the mail server are 3rd party device.
Solution

Before checking why the Email could not be able to receive a report, it is necessary to check if the FortiAnalyzer is able to send Email test to the server or not.

 

  1. Perform a mail test from the CLI:

diag test connection mailserver "server name" <email sender> <email receiver> <- This command will show information about whether the test Email failed or succeeded.

 

 

  1. If it is a success, check the Scheduled reports are not generated.

  2. If it fails, perform a packet capture and download it to be able to check under Wireshark.

 

 

To capture the packet:

 

Go to the System Settings -> Network -> Packet Capture and select 'Create new'.

 

Nur_0-1660370745512.png

 

After, select 'Action and repeat step 1.

 

Nur_2-1660370841497.png

 

After running step 1, note the buttons Stop and Download / upload to Wireshark.

 

Based on the log from wireshark (shown below), it is possible to tell which device has dropped the packet.

 

Nur_0-1660371964544.png

 

By default, FortiAnalyzer will try to use STARTLS. However, when the FortiAnalyzer sends STARTLS, the server sends a 'Policy Violation' and closes the connection.

 

In this scenario, the Email server needs to check why the Email server replies 'Policy Violation' to the FortiAnalyzer.

 

Related articles:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.