Skip to main content
orani
New Member
March 19, 2020
Question

2 Domains / gateway mode

  • March 19, 2020
  • 7 replies
  • 8284 views

My scenario

2 VIPs

1. x.x.x.x --> mx = smtp.domaina.com 2. z.z.z.z --> mx = smtp.domainb.com

I have configured my firewall to NAT traffic to port 25 to Fortimail so the incoming mails to be checked from fortimail. Also i configured fortimail to forward mails to my 2 internal mail servers, servera for domaina.com and serverb for domainb. So all incoming traffic is ok. Also any internal mail traffic is ok. My question is about outgoing traffic.

I configured fortimail to internet traffic throw one vip. So any mail from domaina.com or domainb.com goes throw one vip. Assuming i choose x.x.x.x ip for outgoing traffic, mails from domainb are characterized as spam because there are getting out from wrong ip.

Is there a way to configure fortimail sending mails from domaina.com throw x.x.x.x and mails from domainb.com throw z.z.z.z?

    7 replies

    Dirty_Wizard_FTNT
    Staff
    Staff
    March 20, 2020

    Yeah, you need to differentiate the outgoing traffic by changing the source IP from FML for email from that domain.

    Then you can NAT it accordingly on your firewall to z.z.z.z since you have an alternate source IP to work with.

    With an IP Pool if using FortiGate.

     

    To change source IP for server B; create an IP Policy with server B as the source IP. Consider ordering (place above any policy which would encompass that IP). Then apply an IP Pool on this IP Policy so that traffic matching this IP policy will be sourced as the IP Pool IP when hitting your firewall. Set IP Pool IP in the same subnet as the FortiMail interface for the egress traffic to your firewall.

     

    E.g.: If FML traffic to firewall leaves port1 with interface IP 10.10.10.1/24, you could set IP Pool IP to 10.10.10.2/32.

    orani
    oraniAuthor
    New Member
    March 21, 2020

    This part of configuration i can understand it and i am ok wih this.

    jwilkins wrote:

    Then you can NAT it accordingly on your firewall to z.z.z.z since you have an alternate source IP to work with.

    With an IP Pool if using FortiGate.

     

    To change source IP for server B; create an IP Policy with server B as the source IP. Consider ordering (place above any policy which would encompass that IP). Then apply an IP Pool on this IP Policy so that traffic matching this IP policy will be sourced as the IP Pool IP when hitting your firewall. Set IP Pool IP in the same subnet as the FortiMail interface for the egress traffic to your firewall.

     

    E.g.: If FML traffic to firewall leaves port1 with interface IP 10.10.10.1/24, you could set IP Pool IP to 10.10.10.2/32.

     

    but this part how can it be configured?

    jwilkins wrote:

    Yeah, you need to differentiate the outgoing traffic by changing the source IP from FML for email from that domain.

     

    Dirty_Wizard_FTNT
    Staff
    Staff
    March 25, 2020

    This section was all in reference to FortiMail configuration:

    'To change source IP for server B; create an IP Policy with server B as the source IP. Consider ordering (place above any policy which would encompass that IP). Then apply an IP Pool on this IP Policy so that traffic matching this IP policy will be sourced as the IP Pool IP when hitting your firewall. Set IP Pool IP in the same subnet as the FortiMail interface for the egress traffic to your firewall.'

     

    I understand the structure of my comment made it a bit unclear.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!