FortiSandbox
FortiSandbox provides a solution to protect against advanced threats and ransomware for companies who don’t want to implement and maintain a sandbox environment on their own.
MFARRAG
Staff
Staff
Article Id 358246
Description

This article describes how to configure the FortiSandbox Mail Transfer Agent (MTA) adapter for scanning URLs and attachments within email messages,

Scope

FortiSandbox.

Solution
  1. Ensure that the FortiSandbox MTA license is purchased and activated:

 

MTA-Contract.PNG

 

  1. To enable and configure the MTA adapter, from FortiSandbox GUI, go under Security Fabric -> Adapter, enable the toggle button and configure all required fields like Name of domains that need to be relayed scanned by FortiSandbox adapter, SMTP server IP address / FQDN, SMTP port  as below:

 

FSA5.PNG

 

For adding more one domain can be add it with by comma-separated.

  1. Emails containing malicious URLs or attachments will be scanned and rated by the FortiSandbox MTA adapter, also verify scan results in the Scan Job Details section from FortiSandbox GUI.

 

MTA-File-scan.PNG

 

  1. For managing quarantined emails, navigate to Security Fabric -> Adapter -> Quarantine in the FortiSandbox GUI. This section lists all quarantined emails, and can be able to see:
  • Delete quarantined emails.
  • Release emails.
  • Review the reasons for quarantine and download the mail sample.

 

Sandbox1.PNG

 

FSA2.PNG

 

FSA3.PNG

 

  1. Enable the notification mail setting to alert recipients when their email is quarantined.

 

Quaratine-settings.PNG

 

Notifications will be sent to the recipient's mailbox.


Note:

The FortiMail server mode was used for testing in this example.

 

Notification.PNG

 

  1. To confirm whether FortiSandbox has sent notification emails select Events & Logs in the FortiSandbox GUI.

 

Quaratine-check.PNG

Contributors