Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Saqib_Zafar
New Contributor

FortiMail Threat mitigation steps.

Hello Everyone, I am concerned about how actually fortimail works means how using what deep inside architecture methods or steps a fortimail looks for a Spam or virus. I am well known about how it will capture a spam using Fortiguard options but i if a threat or virus comes in an e-mail how will fortimail recognise that it is a virus or something like that??? I know it will use some heuristic feature and Forged IP and baeysian filtering and so on but what is the basic architecture of a fortimail packet capturing. I have to present Fortimail in comparison with other products so rather than defining features i would like to know the key to how a fortimail scans a packet using what algorithms and methods. Because these features are in Mcafee, Proof Point and so on but tell me some points about how good Fortimail scans using what algo against other products. I will be thankfull to all of you who will answer me.
20 REPLIES 20
Shawn_W

Hi, just checking in to see if white paper was finished.  Thanks.

Wayne11

I would like to know if we can somehow detect Scam or Phishing emails with our FM? Is it possible to flag all emails with different reply to address in the header for example? Thx
emnoc
Esteemed Contributor III

 

For my answers, with scam and phishing email the  reputation of the sender is typically the flag but the FM has under profile URI a phishing tag. It allows you to select various settings  (  phishing maliscious  or categories ). You also want to look at set uri-filter in your  AS profile.

 

For different reply address , you might get by with a X custom header  insertion, but how would trigger it? Also it's not uncommon for a REPLY TO to be different than a sender. If you are not getting AS reputation matches  than I would review your fortiguard services and scoring levels that are set for the AS profile.

 

Give a try and monitor.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Ashik_Sheik

Hi Guys,

 

We are facing issue with fortimail because of Heuristic threshold.

 

I want to increase the threshold but I couldn’t find any document to understand value of that threshold.

What is max value to be set??

 

Current Threshold is :3.50

The Percentage is : 50

 

Regds

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
emnoc
Esteemed Contributor III

I would monitor the logs b4 dabbling with the threshold. In fact you should monitor b4 and after for a  few months and continual.

 

It uses the  the combination of AS scoring results and the define threshold to tag or act upon emails that it thinks are spam. You can adjust the threshold to be lower or higher but monitor the  logs and users and emails that are "thought" to be spam.

 

http://socpuppet.blogspot.com/2015/01/heuristic-options-fortimail_8.html

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Ashik_Sheik

Hi Emnoc,

 

Thanx for the information .I have one more query .How to stop spoofed emails.We are still get email from our own company employee email address .Almost all antispam features are enabled like graylisting ,SPF check etc etc .

 

Regds,

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
Holy

Hello Ashik,

 

just enabling SPX wont help much. Do you have an SPF Record for your domain? if so how does it look like?

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Ashik_Sheik

Hi,

 

We don't have SPF record .What is the alternative method to stop spoofed emails ?

 

 

regds

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
Holy

SPF is the Best method and is easy to configure. You just have to put an txt Record to your Public DNS. Then SPF Check on the FortiMail will work.

 

You can also use DKIM but it more complicated than SPF.

 

Just google for SPF konfigurator, read some SPF Guide and put the Record

 

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Ashik_Sheik

Hi

Thanx .What is the best score for sender reputation.

 

Regds

 

Ashik

 

 

Sheik Mahammad Ashik
Sheik Mahammad Ashik
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors