Troubleshooting Tip: FortiAnalyzer stops sending a report via Email
| Description | This article describes when the FortiAnalyzer can sniffer or ping the Email server, and still could not receive a report. |
| Scope | The issue focus from the FortiAnalyzer site as the mail server are 3rd party device. |
| Solution | Before checking why the Email could not be able to receive a report, it is necessary to check if the FortiAnalyzer is able to send Email test to the server or not.
diag test connection mailserver "server name" <email sender> <email receiver> <- This command will show information about whether the test Email failed or succeeded.
To capture the packet:
Go to the System Settings -> Network -> Packet Capture and select 'Create new'.
After, select 'Action and repeat step 1.
After running step 1, note the buttons Stop and Download / upload to Wireshark.
Based on the log from wireshark (shown below), it is possible to tell which device has dropped the packet.
By default, FortiAnalyzer will try to use STARTLS. However, when the FortiAnalyzer sends STARTLS, the server sends a 'Policy Violation' and closes the connection.
In this scenario, the Email server needs to check why the Email server replies 'Policy Violation' to the FortiAnalyzer.
Related articles: |



