I am slowly migrating from a Barracuda 300 to the FortiMail 200E. I am looking at the logs on the FortiMail 200E and noticed that all of the inbound emails show the same client IP address which happens to be the gateway address of the DMZ network in which the fortimail is installed in. The fortimail is in gateway mode and behind NAT.
I had Sender Reputation enabled until my client IP was getting scored high which delayed all inbound email. Is this normal behavior when installed behind NAT?
Could this also be related to the "Extract IP from Received Header" option that I enabled under my AntiSpam Profile?
Most likely not.
The upstream firewall is probably SNAT'ing the clients behind that one-single address which as you indicated is defeating reputation scoring ;)
Flow trace the sessions and remove the SNAT.
PCNSE
NSE
StrongSwan
Indeed removing the source NAT from my firewall policy resolved the issue. My logs are no longer masqueraded.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.