Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Enabling Google Mail POP through FGT-60

Hi All We have a FGT-60 firewall and we ant to be able to collect Google mail POP through Microsoft Outlook 2003. We have all the port settings necessary entered into Outlook; 995 and 465, and I have added these into the firewall' s policy as an allowed service, but the outlook ' test' mode keeps failing, saying that it can not contact the server. Any advice? Thanks
16 REPLIES 16
UkWizard
New Contributor

make sure of the following; That the outbound policy does allow these ports, and that you are entering them in the right policy (will use the topmost one that applies to the outbound traffic). Check you have the outlook client setup correctly, like this; [link]http://mail.google.com/support/bin/answer.py?answer=13287[/link] As if you fail to select the SSL: yes options, it will not use those ports. Also check you did specify TCP for those port numbers when creating them (if you did) I presume you did ' enable pop' via the gmail site?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

I have the exact same problem. This works on my Sonicwall that is getting replaced by this new FG-100A and all i have enabled for POP mail on that is the POP3 service. Now I' m getting the following error whenever outlook trys to connect to gmail... Task ' pop.gmail.com - Receiving' reported error (0x80042108) : ' Outlook is unable to connect to your incoming (POP3) e-mail server. If you continue to receive this message, contact your server administrator or Internet service provider (ISP).' I have tried the default ports with no luck and the gmail recommended ports 995 & 465 with no luck. Anybody????
UkWizard
New Contributor

its not being blocked by the web filtering is it, something like the webmail catagory?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

No, I am not using web filtering on these services currently. I also created a custom service called GMail using TCP ports 995 & 465 but it still fails to connect. I' m stumped. Isn' t there any logging for this to see what is causing the problem?
UkWizard
New Contributor

you can have a look at the sessions tab and see what sessions you have outbound from that particular pc. Also check that its not flagging up as a Intrusion detection block on the status page. Or you can be more exhaustive and do a packet sniff from the command line, and see what ports are being initiated by the client. using the command like; diag sniff packet internal ' host 192.168.1.1' Where ' internal' is the interface name, and 192.168.1.1 is the initiating clients Ip address. Also, does it work If you create a rule just for that host, to allow unrestricted access to the web, ie no protection profile and no services restricted? This would rule out an other problems, if it works, then restrict the ports and try again, and do the same for the protection profile, turning it on and unrestricting the ports again. this might show up one or the other being the cause.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UkWizard
New Contributor

Oh - Just to confirm, if you have created any custom service entries, make sure the ports you have been provided are ONLY in the destination port number, NOT the source start/from port list. else, it wont work.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

What do I put for the source ports? It won' t let me use 0 for them.
Not applicable

Nevermind previous reply. I fixed it. It was my custom GMAIL service that was causing the problem. I deleted it and setup a new one using only the destination ports as LOW=465 and HIGH=995 (This is a no no. It opens all ports between 465 & 995.. The source ports are LOW=1 and HIGH=65535 and now it works. So for the original poster, create a custom service and set it up that way and it should work. Thanks for the help UKWizard!!!!
UkWizard
New Contributor

Whatever you do, DO NOT LEAVE IT LIKE THAT. You have essentially opened up every port between 465 and 995. Instead, do like my example above, create one tcp entry for 465 to 465 and another or 995 to 995 instead.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors