understanding fortigate policies
I am not 100% sure if this is the correct place to post this question, if not please let me know and I will re-post.
We use a Fortigate 200D with version 5.4.6 firmware. I am trying to get a better understanding on how traffic works when it comes to adding policies - both lan to wan and wan to lan. The trouble I am having is understanding if I need both internal to external as well as en external to internal policy set up for a specific application.
For example: we use lotus notes client for our emails and our mail server is hosted at an external location. I am wanting to set up secure communication to and from the mail server. with required IPs, ports and services, instead of all, all and all.
So here come the questions: 1. Do I set up an out going profile (lan to wan) to allow communication from the client to the mail server externally? (this one is a given) 2. Do I also set up a second profile (wan to lan) to allow external traffic from mail server to client? When lotus notes client requests/send email it uses a replication process to do this. I hope this makes sense as to what I am trying to ask/understand. Thank you
