FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
opetr_FTNT
Staff
Staff
Article Id 193275

Description

 

This article explains how to disable services AUTH, POP3(S), and IMAP(S), which are enabled on FortiMail platform by default, but may be unnecessary in some environments.


Scope


FortiMail v4.0 MR3.


Solution

 

By default, the FortiMail advertises for SMTP, TLS, and SMTPS that SMTP AUTH can be used:

 


220 gateway.lab.net ESMTP Smtpd; Thu, 31 Jan 2013 17:30:42 +0100
ehlo test.lab
250-gateway.lab.net Hello [192.168.196.98], pleased to meet you
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-8BITMIME
250-SIZE 10485760
250-DSN
250-AUTH LOGIN PLAIN
250-STARTTLS
250-DELIVERBY
250 HELP

# config system mailserver
(mailserver) # set smtp-auth disable
(mailserver) # end

220 gateway.lab.net ESMTP Smtpd; Thu, 31 Jan 2013 18:06:27 +0100
ehlo test.lab
250-gateway.lab.net Hello [192.168.196.98], pleased to meet you
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-8BITMIME
250-SIZE 10485760
250-DSN
250-STARTTLS
250-DELIVERBY
250 HELP

# config system mailserver
(mailserver) # set smtp-auth-over-tls disable
(mailserver) # set smtp-auth-smtps disable
(mailserver) # end

# config system mailserver
(mailserver) # set pop3-service disable
(mailserver) # end

# config system mailserver
(mailserver) # set imap-service disable
(mailserver) # end

 

Via the GUI:

  • Navigate to System -> Mail Settings
  • Disable the IMAP(S) by the button in 'IMAP Service'
  • Disable the POP3(S) by the button in 'POP3 Service'

 

Screenshot 2025-03-12 at 14.28.24.png