FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kcheng
Staff
Staff
Article Id 239749

Description

 

This article describes how to fix the situation where it is impossible to configure 'Default Reply To' via GUI and CLI. This is only available for certain version, and completely removed from newer FortiOS versions starting with v7.4.4. There is no current plan to reintroduce the "set reply-to" command in the future.

 

Scope

 

FortiGate v6.4.10 and above, v7.0.8 and above, v7.2.0 and above - until v7.4.4, v7.6.0

 

Solution

 

In the versions specified above, when the default Fortinet email server is used, the reply-to version is no longer configurable.

The default 'reply-to' email address that will be used is DoNotReply@fortinet-notifications.com for the Fortinet notification server. This can only be used by units with valid Fortinet support contracts. It cannot be changed.

 

In GUI, when the Default SMTP server is selected, there will not be an option to configure Default Reply-To. The notification servers have also been changed, as seen below:

 

email3.jpg

 

On the CLI, there will be no option to configure the respective option either:

 

kcheng_1-1671091031779.png

 

The respective option is only available if the custom email server is used:

 

kcheng_2-1671091087526.png

 

The respective CLI command is also possible only if the custom email server is selected:

 

kcheng_4-1671091193138.png

 

In the newer versions (after v7.4.4 and v7.6.0), the 'reply-to' option is removed completely, also for custom servers.

In this case, the email will be sent from the authenticated user defined for that email server, or if this user is not set up, the email will be sent with the same value in 'To:' and 'From:' fields. The difference is seen below (w/o authentication):

 

emailserver.png

 

Following these changes, using certain custom servers without authenticated users, like Outlook, or Gmail, has become impossible due to extra checks on the reply-to-address value.

 

Related documents:

Resolved issues v6.4.10

Resolved issues v7.0.8

Resolved issues v7.2.0

Updated default email notification server (Release notes 7.4.4)