Hi !
I hava mail server (Postfix) in DMZ. Now I' m trying to deploy FortiMail in Gateway Mode. Topology is like on pic below.
Situation :
I have only 1 public IP and (in example) :
LAN = 192.168.1.0/24
DMZ = 10.0.0.0/24
DNS is external (some provider' s server)
FortiMail = 10.0.0.2
Postfix = 10.0.0.3
FQDN of server always have been mail.domain.com
Users have email addresses like user@domain.com
All emails are send from " users" @domain.com (NOT i.e. from user@mail.domain.com !)
SMTP server require auth.
Cert on server is selfsigned.
Everything works OK.
Now I' m trying to set up FortiMail in Gateway Mode and change settings od FortiGate firewall - forward SMTP traffic (Virtual IP) not to Postfix but to FortiMail.
On Postfix I can setup FortiMail as " smarthost" - but it' s not necessary - Posftix will send mail directly to Internet (I suppose it' s OK) with my public IP.
Fortimail have to have correct name (corresponding DNS record) so I setup name the same as Postfix.
This configuration works ALMOST ok. Recieving is OK, mails are coming.
The only problem is when users want to SEND email and they have in email client software server set to mail.domain.com (if they could have internal IP of Postfix all could works OK but there are mobile users too - so that' s not the point ).
When they try to send enything they are alawys asked about user and password and never authenticated !!!
I don' t want to setup FortiMail as Open Relay so how to force FortiMail to " push" authentication process to server 10.0.0.3
I setup fortimail policy to " authenticated" but it' s still not working.
What I should do ?
What could be wrong with it ?
Dominik Weglarz, IT System Engineer