Description | This article describes how to resolve the issue where the policy that should allow traffic to smtp.office365.com on port TCP 587 is not working consistently, resulting in periods where the connection is blocked and periods where it is allowed. |
Scope | FortiGate. |
Solution |
To solve this problem, the dynamic nature of the FQDN address of smtp.office365.com was identified as the root cause, which resolved to different addresses on FPMs and was addressed by increasing the cache TTL for the FQDN to 24 hours.
Here are the step-by-step instructions to carry out this solution:
Ensure Policy ID (Policy ID number) is correctly set up to allow traffic from the specific source to smtp.office365.com on port TCP 587 (Port 587 is commonly used for SMTP (Simple Mail Transfer Protocol) for mail submission. It is designated for client-to-server communication, facilitating the sending of email messages to the mail server. It is technically possible to change the port number as long as the service/server communicating with supports the port number changed to).
Confirm that DNS settings are correctly synchronized between the firewall and the server.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.