Skip to main content
Fullmoon
New Member
March 9, 2019
Question

internal email communication

  • March 9, 2019
  • 2 replies
  • 3888 views

what would be the best approach to enforce better security if sender and recipient coming from same domain?

in such case user1@example.com is infected of malware/riskware and keeps sending emails to user2@example.com and etc...

 

How fortimail will address thus of dilemma?

 

I installed my Fortimail in gateway mode. Two possible setup; Fortimail and Mails Server resides on same subnet or Mail Server located in LAN and FortiMail is located in DMZ

 

Any thoughts are much welcome and appreciated.

    2 replies

    Contributor III
    March 16, 2019

    FortiMail should have 1 internal IP address and 1 external IP address. 

     

    Block access to Email server, except when requests comes from FortiMail's Internal/External IP address.

     

    Above will force Internal users to send emails through FortiMAIL. 

     

     

     

    Seppel
    New Member
    March 16, 2019

    you can also use the fortimail and the mailserver in the same subnet. the direct access to the mailserver you can limit over the firewall before the dmz. You can restrict the receipt of external mails with your domain as the sender via a receiving access policy. 

     

    Sender abc@yourdomain.com -> fortimail -> Access Control rule -> discard/deny -> mailserver @yourdomain.com

    Sender abc@abc.com -> fortimail -> Access Control rule -> relay -> mailserver @yourdomain.com

     

    receiving Access Control rule:

     

    Sender pattern: *@yourdomain.com

    recipient pattern: *@yourdomain.com

    Sender ip: 0.0.0.0/0

    Action: dicard

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.