Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Blocking outgoing email

Is it possible to block outgoing emails in a certain domain range. I have an infected computer behind my firewall that is sending spam, but I cannot figure out which computer it is because it is a student owned computer and I have alot of them to check and that takes time. I know the approximate times it sends, but cannot find out what unit it is because we have no fortianylizer to archive the data, all I can see is that it is leaving in my email content archive. I cannot find anything in the protection profile, so I am stumped. Thanks for any help. I have a Fortigate-60 3.00,build8845,080730 Here is part of my log that I get, I can only see the last 64 transactions from last night. 2009-04-21 09:04:11 email address@painkillerdetox.com email address@bb-sportnahrung.de support your sexuality 2009-04-21 09:04:12 emailaddress@thing.net emailaddress@provincia.so.it hoist your lover night event
3 REPLIES 3
rwpatterson
Valued Contributor III

Block SMTP from the student IP range outward. Actually it should be blocked for all but corporate email servers...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
red_adair
New Contributor III

Did you think about " log allowed traffic" for a tcp/25 (smtp) rule and log this to a standard Syslog-server ? This should reveal at least the senders IP. You can also go to " AntiSpam" and write your own rule. For example " emailadress" -> Wildcard (Regex) and have your domain marked as clear. Than create a PProfile for outgoing SMTP and apply this to AntiSpam Section within the PProfile. Action for SPAM would be " discard" . Outgoing SPAM will be discarded. Trigger for being SPAM will be if an email is not having a certain domain-name. -R.
Not applicable

Thanks for the help, I created a new profile that blocked the students from SMTP and this has stopped the spam, I am now trying to log all violations, but have had limited success so far. I may try the opposite way where I let the info go and log for a couple of hours, but I also need to get my syslog server receiving more info, only some events are being passed so far.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors