Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Filtering SMTP outbound

My site is being blocked at cbl.abuseat.org for propagating spam. The cbl website says I should block all outbound SMTP traffic except from my email servers address. I created a rule allowing outbound SMTP from the email server' s address to any address. Below that rule I added a rule denying all SMTP from any address to any address. When I did this I then looked at the traffic logs to see what SMTP traffic was being blocked and allowed. I observed that the port 53/dns traffic from my email server showed packets sent but not received. If I disabled thte rule there was no changed. When I removed the rule the dns queries received responses and I stop getting 450 host down messages when my email server tried to send a message. Wha is the correct way to implement SMTP filtering on te fortigate unit. I am running Fortigate 2.80 OS.
5 REPLIES 5
abelio
SuperUser
SuperUser

simpler: if you think that your SMTP server it' s not a spam source or open relay, remove its IP address from cbl.abuseat.org following the standard procedure provided by them. If you' re one spam source or open relay....you have not a Fortigate problem. Regarding your policies settings, it' s not clear if you' ve set a VIP with static nat or port forwarding for your SMTP service; please provide more info: is your external VIP address blacklisted or is your wan IP blacklisted?

regards




/ Abel

regards / Abel
Not applicable

There is no open relay on my email server. I suspect I have workstations in my network sending spam over the smtp port. My external WAN IP is blacklisted. I did not use a VIP in my policy, I used the Firewall -> address function. Is this perhaps where I made my mistake? Should I create a VIP internal IP/port 25 to external IP/port 25. Is fortigate staeful like a PIX, in that any internal traffic that sends traffic is allowed a response without explicit permission from the firewall? In the mean time I have blocked the workstation that was sending lots of traffic. Now I notice that my Barrucuda spam appliance is showing up as a large sender in the event log, but it is only supposed to take received mail from fortigate, scan it, then forward it to the email server. Why does it show in the source column of the event log?
Not applicable

As they said, its abnormal to let users sending email directly on internet from their workstation. Your SMTP server should be the only one allowed to send email. For the firewall rules, Yes the firewall is working in stateful mode. The more specific rules must be placed on top of others. Normally the default outgoing rules should be set to " DENY" as soon as all rules are created.
Not applicable

Here is my final solution. I am going to have my email server send mail on port 26. Then I will have the fortigate translate that port on incoming and outgoing mail. Finally I will have the fortigate drop all outbound port 25 traffic. This will give me breathing room to make sure all 1500 of my machines are clean and virus protected.
UkWizard
New Contributor

t
Here is my final solution. I am going to have my email server send mail on port 26.
thats the strangest thing i have ever heard .... What you should do is create an service group containing necessary services that the mail server needs, which includes SMTP and DNS, and use this in the accept rule. Then the deny rule wont block the DNS queries. What you may want to watch out for, is that your barracuda box isnt being an open relaying and spammers are bouncing email off it externally. Check the barracuda logs to make sure that emails are either being blocked or allowed if the domain is your internal one only. There are a few open relay online tests you can do to test whether you are an open relay as well.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors