Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Alias and Groups Webmail Quarantine Issues

Hi All, I' m looking for some insight here as I' ve had my ticket opened with Fortinet Support for nearly 4 weeks and still haven' t found a resolution. The problem is that we have a lot of aliases and distribution groups in our Exchange environment. After moving to the Fortimail 400B, our users can only see the quarantined messages in their primary accounts when logging into their webmail. Messages that were caught in their alias accounts are not visible to them after logging in. When we configure " User Alias Options" in our LDAP profile we select Active Directory as our schema, add our base and bind dn' s, provide the bind password, and accept the remaining defaults. Page 333 of the Fortimail Admin Guide v4.0 Patch 1 states the following. " For some schemas, such as Microsoft ActiveDirectory-style schemas, this query will retrieve both the user’s primary email address and the user’s alias email addresses. If your schema style is different, you may want to also configure User Alias Options to resolve aliases." Page 336 " If you want to define a user alias query, enable User Alias Options, click the arrow to expand its options, and configure the query. Resolving aliases to real email addresses enables the FortiMail unit to send a single quarantine report and maintain a single quarantine mailbox at each user’s primary email account, rather than sending separate quarantine reports and maintaining separate quarantine mailboxes for each alias email address. For FortiMail units operating in server mode, this means that users need only log in to their primary account in order to manage their spam quarantine, rather than logging in to each alias account individually." Now my Fortimail is running in Gateway mode so does the above statement not apply? If it only works in Server mode, how do I get the Fortimail unit to display the quarantined message for my aliases in groups via webmail? Sorry for the long write up. Mike
20 REPLIES 20
romanr
Valued Contributor

When we configure " User Alias Options" in our LDAP profile we select Active Directory as our schema
I think I got working, what you want! The predefined AD Scheme from Fortinet didn' t wok for me! What I use is: Schema: User Defined Alias member attribute: mail Alias member query: (&(|(objectClass=User)(objectClass=Contact)(objectClass=Group)(objectClass=publicFolder)) (|(proxyAddresses=smtp:$m)(mail=$m))) Group member Attribute: member Group member query: (&(objectClass=group) (proxyAddresses=smtp:$m)) regards, Roman
Not applicable

Hi Roman, Thank you, I' ve modified my LDAP profile to match yours but it still does not seem to be working right. I' ve verified via ADSIedit that the proxyAddresses attribute contains my primary and alias SMTP accounts which makes your query string sound much more accurate than the Fortimail default. I' ve sent myself a test spam message to my alias mike@domain.com to trigger a quarantine. When I attempt to login via webmail with that alias it give me an invalid user error. So I log in with with my primary account (mikek@domain.com) and it takes it but my quarantine is blank. It seems that there are 2 separate quarantines (1 for my primary and 1 for my alias) and I have no way of viewing those items that get stuck in my alias. Thanks again for your help, this Fortimail is giving me headaches! Mike K.
romanr
Valued Contributor

Hi Mike, what Fortimail Version do you use. I used this config quiet some time with V3 and now with V4 and don' t have a problem! Have you tried the " Test" option in the LDAP-profile section? What will alias-testing tell you there? To tell everything about LDAP config -> I also use a custom filter for user quering and I do not use the Fortimail default: " (&(|(objectClass=User)(objectClass=Contact)(objectClass=Group)(objectClass=publicFolder)) (|(proxyAddresses=smtp:$m)(mail=$m)))" cheers.roman
Not applicable

Fortimail 400B Firmware: v4.0,build0103,091223 (GA Patch 1) When I use the LDAP Query Test I receive strange results. Query type = User Both my primary and alias are found. Query type = Alias None of my accounts are found. Do you use a custom filter for your " User Query" options as well? My " User Query" is using the Fortinet Active Directory default. Thanks.
romanr
Valued Contributor

Do you use a custom filter for your " User Query" options as well? My " User Query" is using the Fortinet Active Directory default.
Yes! I just posted my filer in my last post! And I remember also light troubles getting this to run! I think I came across a situation, where I had to reboot the box before it worked! regards,roman
Not applicable

Strangely, my Fortinet default for " User Query Options" looks like our custom except for the (objectClass=Contact).
romanr
Valued Contributor

ORIGINAL: mikek_cci Strangely, my Fortinet default for " User Query Options" looks like our custom except for the (objectClass=Contact).
Yes, you will need this one for mails routed as external contacts! Otherwise your Fortimail wouldn' t accept them!
Not applicable

Ok, just so I' m clear on this the setup looks like this. User Query Options Schema: User Defined LDAP user query: (&(|(objectClass=User)(objectClass=Contact)(objectClass=Group)(objectClass=publicFolder)) (|(proxyAddresses=smtp:$m)(mail=$m))) User Alias Options Schema: User Defined Alias member attribute: mail Alias member query: LDAP user query: (&(|(objectClass=User)(objectClass=Contact)(objectClass=Group)(objectClass=publicFolder)) (|(proxyAddresses=smtp:$m)(mail=$m))) User group expansion in advance: *checked* Group member attribute: member Group member query: (&(objectClass=group)(proxyAddresses=smtp:$m))
romanr
Valued Contributor

User group expansion in advance: *checked*
Nearly, everything looks the same but, user group expansion is NOT checked... I remember this didn' t work!!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors