FORTIMAIL Gateway mode - Not seeing email traffic in FortiMail VM
Good day,
I am new to Fortinet, I am use to the Cisco product line and wish to expand my knowledge further, using Fortinet products way forward.
Mode chosen: Gateway mode
Deployment type: Forti mail in the DMZ or Behind the FortiGate
Could someone kindly assist me step by step(probably u did for your environment/similar if possible) how to carefully deploy a Forti mail VM to manage and monitor my email traffic in Gateway mode. I have read via the 7.4.1 admin guide, other admin guides, watched a few YouTube videos and NO real guidance, step by step solution, not even a workable template based setup for Forti mail, just a bunch of webinars, chatting and simple setups(telling/referring you to go read this entire document(admin guide), no real lab scenarios at all. I have configured/setup and deployed many devices, network solutions in infrastructure environments/datacenters, some all by myself, others with help of comrades, video guides and straightforward - coherent reading material. But I am stuck here and need your guidance
Network Environment Details but not limited to below(If you need more information, such as a simple network diagram of the intended setup, let me know):
1. One(1) email/exchange server behind the firewall/internal LAN e.g. 192.168.5.6
2. One(1) HW FortiGate Firewall (with both WAN, LAN, DMZ interface etc. setup)
3. 1 Private DNS server/PDC behind the firewall/on internal LAN e.g. 192.168.5.2
4. One(1) mail relay server(VM) running Postfix in the DMZ in front of FortiGate e.g. on diff subnet 192.168.70.3
5. A public/WAN IP address already mapped to the email relay VM internal IP
6. Firewall Policies for SMTP traffic to flow between email server, mail relay and internet(incoming-outgoing)
Intention: Is to replace the email relay VM(putting it offline) with the newly installed Forti mail VM in DMZ for email traffic flow/ protection or keep Forti mail behind firewall and continue using email relay.
What I have done so far:
1. Registered Forti mail license and VM in Fortinet Asset management
2. Downloaded Forti mail VM
3. Configured/setup VM via Hyper V successfully.
4. Started VM and deployed successfully
5. Configured VM nic1 interface via CLI with IP e.g. 192.168.5.7
6. Ran/followed via wizard, entered protected domain, DNS, Mail server settings, Admin credentials etc. input gateway IP so that Forti mail can ping externally.
7. Applied Fortinet registered license to Forti mail VM successfully
8.Connected Forti mail to Forti guard successfully.
Now for the concerns/queries:
1. I watched this video and it provided no real help. How did he even achieve to get mail event logs/email traffic, what am i missing, i copied all his steps but using my network details/IPs of course) - https://www.youtube.com/watch?v=4AAWRrryzX0
2. I watched this video and it is not fully informative, just superficial - https://www.youtube.com/watch?v=jdemC9cGvdM
3. I am confused about some details on this page - https://docs.fortinet.com/document/fortimail/7.4.1/administration-guide/932807/gateway-mode-deployment#install_4107377314_1049174
Such as:
- You must configure public DNS records for the protected domains and for the Forti Mail unit itself
- Configuring DNS records for the protected domains?
- Configuring the firewall policies for email traffic (incoming and outgoing) between the Forti mail, FortiGate and Email Server.
I know about DNS records on AD, creating/configuring them etc. But it says in this document public DNS etc.
- I do not have a public DNS server in front of the firewall/on the internet
- I only have a private DNS server
- For .e.g. in my environment, I have a "Batteries. Local" domain on the Domain Controller/s, but our users at the batteries company uses the "batteries.com.au" domain from the Local Email Server. In the admin document it refers to protected domain, what should I enter for protected domain during Forti mail wizard setup the .local or the .com.au domain?
- Also which Host A record on my private DNS should i use for the Forti mail VM, a wan/public IP or local/Lan IP for the Forti mail?
On the FortiGate I see the address entry for the following :
1. Email Relay VM(DMZ IP)
2. Email Server(local/private IP)
3. DMZ subnet
4. LAN/Internal Subnet
On the FortiGate I see IPv4 Policy entries as follows but not limited to:
1. (WAN to DMZ)allow smtp to relay - (source: all , destination: mail relay , schedule: always , service: smtp , action: accept)
2. (DMZ to LAN) - (source: all, destination: local mail server , schedule: always, service: smtp, action: accept)
Please note:
-On my DC, there are no mx records, so how is name resolution taking place? There is only a Host A record for the Exchange server.
-Whenever I do a NSLOOKUP or PING on mail.batteries.com.au, I see the public/wan mapped IP of the mail relay(postfix VM) that is on the DMZ
- There are no FortiGate entries for the Forti Mail VM
Currently, the deployed Forti mail VM is just sitting there doing nothing. Anyone, please help!
