Skip to main content
Contributor III
April 21, 2009
Question

Blocking outgoing email

  • April 21, 2009
  • 3 replies
  • 6070 views
Is it possible to block outgoing emails in a certain domain range. I have an infected computer behind my firewall that is sending spam, but I cannot figure out which computer it is because it is a student owned computer and I have alot of them to check and that takes time. I know the approximate times it sends, but cannot find out what unit it is because we have no fortianylizer to archive the data, all I can see is that it is leaving in my email content archive. I cannot find anything in the protection profile, so I am stumped. Thanks for any help. I have a Fortigate-60 3.00,build8845,080730 Here is part of my log that I get, I can only see the last 64 transactions from last night. 2009-04-21 09:04:11 email address@painkillerdetox.com email address@bb-sportnahrung.de support your sexuality 2009-04-21 09:04:12 emailaddress@thing.net emailaddress@provincia.so.it hoist your lover night event

    3 replies

    rwpatterson
    New Member
    April 21, 2009
    Block SMTP from the student IP range outward. Actually it should be blocked for all but corporate email servers...
    red_adair
    New Member
    April 21, 2009
    Did you think about " log allowed traffic" for a tcp/25 (smtp) rule and log this to a standard Syslog-server ? This should reveal at least the senders IP. You can also go to " AntiSpam" and write your own rule. For example " emailadress" -> Wildcard (Regex) and have your domain marked as clear. Than create a PProfile for outgoing SMTP and apply this to AntiSpam Section within the PProfile. Action for SPAM would be " discard" . Outgoing SPAM will be discarded. Trigger for being SPAM will be if an email is not having a certain domain-name. -R.
    Contributor III
    April 22, 2009
    Thanks for the help, I created a new profile that blocked the students from SMTP and this has stopped the spam, I am now trying to log all violations, but have had limited success so far. I may try the opposite way where I let the info go and log for a couple of hours, but I also need to get my syslog server receiving more info, only some events are being passed so far.
    Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
    Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.