Question
How to stop SMTP flooding
I support a client who has a FG100A that has always been hit VERY hard with SPAM. I finally got the go-ahead to upgrade to build 318 recently. Until that update was applied I wasn' t convinced the Fortigate was blocking much SPAM. After the update SPAM detection was increased significantly and a high percentage of the SMTP traffic was being dropped. Today my client called me to say that their internal users can' t get out to the Internet. To make a long story short, they' re getting hit really hard by SPAM and it' s completely saturating their broadband connection. It takes me about 3 minutes to log into the Fortigate from outside their network. From the inside it' s very quick which confirms that the attack is coming from the outside. I contacted support who checked my settings and confirmed for me that this is the case. He noticed the CPU usage (12%) and Memory Usage (46%) were in the acceptable range so he was convinced the Fortigate wasn' t being over-taxed. When we disable the policy that allows incoming SMTP traffic everything works fine. As soon as I turn that policy back on I have over 1500 SMTP connections in 30 seconds. The connections seem to be coming from all different IP addresses. The tech suggested setting IPS/IDS to drop certain SMTP sessions which he said he did. I don' t see where he did this though. Today I upgraded to v3.0 build 400 and we still have the same problem. Does anyone have any suggestions on how to handle this kind of problem? On top of this there are no IPS statisitics on the status page so I' m not convinced that any SMTP " attacks" are being detected. HELP! My client is effectively dead in the water if I turn on SMTP and if I turn it off he can' t receive email. Thanks in advance.
