Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
OvidiuCiobanu
New Contributor

Checking process of invalid quarantine accounts removal

Hello, We have a FortiMail 100 in Gateway mode and one main mail domain. For this domain we reached >120.000 personal quarantine mailboxes. Old sysadmin forgot to enable " Automatic Removal of Invalid Quarantine Accounts" . I have enabled it few weeks ago (from SMTP server) but the number of quarantine accounts is the same. Is there any way to check the process or its logs? The config is default at 4am - and in web interface logs is nothing at that time. Thank you
8 REPLIES 8
ehlo
New Contributor

Ovidiuciobanu. What firmware version are you using? If not the latest one, you can try to upgrade it and then monitor it. ehlo
OvidiuCiobanu
New Contributor

Hello, We use Firmware version: v4.0,build0510,120718 (MR3 Patch 2) - last one per my knowledge. 128000 personal quarantine mailboxes now. I tried to delete some manually - and i found also that we cannot either manually delete fake mailboxes - at the beginning these start with +._ like an example +._-0thicken1955@.... I mean i select some mailboxes, press Delete - yes - then page refresh and mailboxes are still there. Is there any command line to delete some mailboxes? I suspect the removal task cannot delete these also. Thank you
OvidiuCiobanu
New Contributor

So nobody knows how this process can be manually started, debugged or see its log? Thank you for any info
ehlo
New Contributor

OvidiuCiobanu, Since manual deletion is not working, it does not hurt if you could try the scheduled one. If it found this user not existing on backend server, it will delete them. ehlo
OvidiuCiobanu
New Contributor

Thank you for reply By scheduled one you mean the " Automatic Removal of Invalid Quarantine Accounts" backend process? It is enabled and does nothing. I suspect it even did not start. I cannot find anything about this process - log, process name or any valid info. If you mean another way of scheduled deletion of some users i am keen to find about that. Best regards
romanr
Valued Contributor

Hi, have you really had this 128000 mailboxes on your internal mail-server? Or was there no checking of recipients/aliases? Do you have a proper LDAP/Radius/SMTP checking of your recipient accounts? Because this will be necessary for the quarantine removal to work! best regards, Roman
OvidiuCiobanu
New Contributor

No, checking was disabled and that was the result. I have enabled it one month ago but no results. please explain a bit what means " proper SMTP checking" ? what should be server reply? Thank you
romanr
Valued Contributor

Hi, which protocol do you use for your recipient checking? With LDAP there is a test-function to see if recipient checking and aliases resoving do work... I don' t know for radius or SMTP... Also check your mail-server! Some mail servers will accept *@domain.com on the SMTP layer... If this is the case, then won' t have a chance if you use SMTP for recipient checking... br, Roman
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors