FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kcheng
Staff
Staff
Article Id 316811
Description This article describes the change of the default Fortinet SMTP server from ‘notification.fortinet.net’ to ‘fortinet-notifications.com’.  
Scope FortiOS v7.4.4 and above.
Solution

Starting from FortiOS v7.4.4, the default SMTP server in FortiGate has been changed to 'fortinet-notifications.com', and valid FortiCare support is required to use the default SMTP service.

Eamil.png

 

The user will still be able to configure the details for email action:

 

email_action.png

 

However, the email would not be sent if there is no valid FortiCare support for the FortiGate. This can be validated by enabling the debug for alertmail daemon:

 

diag deb app alertmail -1

diag deb en

 

Log.png

 

It clearly indicates that the device has no active FortiCare support and hence, the default fortinet-notifications.com cannot be used:

 

Log: "Cannot use fortinet-notifications.com when forticare support is invalid."

 

This has been documented in FortiOS v7.4.4 release notes:

Default email server available to registered devices with FortiCare

Check if FortiGate is showing FortiCare support as registered.  This can be checked in the GUI on the dashboard with the licensed widget. Hover the mouse over the Support icon to see the status of FortiCare support. 

 

01-license.jpg

 

If support is not shown as valid verify if there are any connectivity issues to FortiGuard.

To troubleshoot connectivity issues to FortiGuard see: Troubleshooting Tip: Unable to connect to FortiGuard servers.

 

If the FortiGate is part of an HA cluster, verify that the licensing is the same for each unit.

Verify if the units are registered to the same FortiCare account.

To troubleshoot this issue see: Troubleshooting Tip: License not updating when FortiGate on HA have Different Account Registration.

 

For the FortiGate-VM, use the Fortinet's default email server as a workaround only when the device has enhanced or comprehensive-level entitlements, but FortiGate-VM does not have enhanced or comprehensive-level entitlements, which results in the error 'Cannot use fortinet-notifications.com when Forticare support is invalid'.
The only option left is to downgrade the unit to v7.4.3 or wait for the issue to be resolved in v7.4.5 or v7.6.0.