Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CL1
Contributor

Disabeling Fortimail domain

Hello everyone,

 

Is there a way to create a domain in Fortimail but disable it without deleting it ?

 

Kind regards,

CL
CL
6 REPLIES 6
AEK
SuperUser
SuperUser

Hi CL1

It seems there is no switch in GUI or CLI to disable/enable a domain.

Nevertheless if you mean by disabling it not to send/receive a mail from or to yourdomain.com, then you should be able to achieve it by adding 2 access control rules as follow:

1- Deny outbound from yourdomain.com:

  • Sender: *@yourdomain.com
  • Recipient: *
  • Source: IP-of-your-mail-server
  • Action: Reject

2- Deny inbound to yourdomain.com:

  • Sender: *
  • Recipient: *@yourdomain.com
  • Source: 0.0.0.0/0
  • Action: Reject

An put those 2 rules at top.

Didn't test it but I think it should work.

When you want to enable the domain you just need to disable/delete those 2 rules.

AEK
AEK
CL1
Contributor

Hi AEK,

 

I just want to create the domain and perform the necessary configurations in preparation for a future migration. That’s why I’d like to keep it disabled for now. Thank you for the suggestion, however, in my case, it wouldn’t be helpful as it would block legitimate emails.

 

Kind regards,

CL
CL
AEK

Hi CL1

Which legitimate e-mails you mean? If the domain is not in production yet then e-mails from or to yourdomain.com should all be considered as illegitimate and should be blocked. And that's exactly what perform the above rules. Or did I misunderstand your requirement?

AEK
AEK
CL1
Contributor

Hi AEK,

 

The domain is currently running on an external mail server and will soon be migrated to FortiMail. I just want to set up the necessary configurations in FortiMail ahead of time, so when the migration happens, everything is ready. That’s why I’d like to create the domain now and keep it disabled until it goes live. After the migration, Fortimail will handle two domains, one that’s already in production in Fortimail and the other being moved from the external server to Fortimail.

 

Kind regards,

CL
CL
AEK

Hi CL1

One other possible solution is the following:

  1. Backup the current FML config as backup_old.conf
  2. Add the new domain config to FML (domain, policies and all)
  3. Backup the new config as backup_new.conf
  4. Restore backup_old.conf

The above should be done during off hours.

And once the domain is migrated to the internal server then you just restore to restore backup_new.conf

Hope it helps.

AEK
AEK
CL1
Contributor

Hi AEK,

 

That is actually a good alternative, I like the idea. Thanks for the help.

 

Kind regards,

CL
CL
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors