Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Fortimail 100 issues

Just few days ago i acquired Fortimail-100 so i' m new to all fortimail settings. Setting i' ve done so far: 1. updated firmware now is 3.00, build204 2. Operation mode- transparent, basically fortimail-100 sits between firewall and mail server, same subnet. 3. opened udp 8889 and 9443 ports on firewall settings 4. configured policy (recipient based), antispam etc. Now the issues i experienced: 1. for some reason the updates dont work. under System\Update --> FDN status: not available Push Update: Unknown i even opened 9443 port for push updates. 2. i' m a bit confused with Mail Settings prior to 3.0 patch the local domain name and domain name must have been different, that should not matter in 3.0 patch. changes i' ve done: under Mail Settings\Settings --> Local Domain Name i set: fortimail.company.local under Mail Settings\Domains --> i' ve created: FQDN which is mail.company.com and used SMTP IP address. no MX. imo these abovementioned settings should be OK. However, when i tried to send Alert email found under Log&Report\Alert Email. The alert emails are put into the queue (Mail Settings\Mail Queue) with following Reason: Deferred: Name server: company.com.: host name lookup failure and just sits there and retry. 3. under System\Status\Mail Statistics whenever i hit it i' ll get none. looks like the fortimail isnt filtering nor processing any emails. 4. forgot to mention my environment exchange 2003. havent done any changes. any help much appreciated. thank you Jesi
4 REPLIES 4
RickP
New Contributor

1. Is your firewall a NAT device? If so, you need to set up fort forwarding for push updates to work. The reason is the FortiGuard server sends a notification that there' s an update, and this is not getting though. Opening 9443 isn' t enough. But of course, your FortiMail unit will need to contact the FortiGuard servers when it receives the notification. Can the FortiMail unit get out on port 8890? That' s what the FortiMail unit will use to contact the FortiGuard servers. 2. I' m not entirely sure about this one because I haven' t ever used subdomains. My config uses company.com for both the local domain name and my only defined domain in Mail Settings > Domains. I entered mailgw in the host name field. You say " i' ve created: FQDN which is mail.company.com and used SMTP IP address. no MX." Did you first create company.com and then create mail.company.com as a subdomain of company.com? I ask because I don' t think simply creating test.company.com would work properly. If the mail to your local users comes in as xxx@company.com, I don' t think the FortiMail unit will recognize it if it is configured with a domain of mail.company.com. As I say though, I have little experience with subdomains so I' m not sure about this. 3. This could be related to issue 2.
Not applicable

sry i made a mistake not 8889 port but 8890 (mistypo) 1. yes, it is NAT. i set 8890 and 9443 ports for forwarding. still not working i' ll try to insert pic next time. 2. nah i didnt set any subdomains. i' m just confused with the local domain name and FQDN name. perhaps, i should use same? cheers,
RickP
New Contributor

1. yes, it is NAT. i set 8890 and 9443 ports for forwarding.
You don' t need to forward 8890. The FortiMail unit needs to get out on this port...no connections come in. It seems that the FortiMail can' t contact any FDN servers on 8890. If your FDN status is still ' not available' you need to get this straightened out before you worry about push updates.
Not applicable

I can comment on part of this as we had the exact same problem.
changes i' ve done: under Mail Settings\Settings --> Local Domain Name i set: fortimail.company.local The Domain Name looks right but if it' s any help we have our Local Domain as forti.fort.domain name under Mail Settings\Domains --> i' ve created: FQDN which is mail.company.com and used SMTP IP address. no MX. We tried running the box with SMTP IP address this doesn' t work for some reason. Try ticking MX record and on your DNS server setup the Forward Lookup Zones for each domain you recieve mail on. imo these abovementioned settings should be OK. However, when i tried to send Alert email found under Log&Report\Alert Email. The alert emails are put into the queue (Mail Settings\Mail Queue) with following Reason: Deferred: Name server: company.com.: host name lookup failure and just sits there and retry. We recieved emails in deferred mail because we didn' t setup forward zones for all our domains so the box didn' t know where to route the mail, once we figured out the problem everthing started working. 3. under System\Status\Mail Statistics whenever i hit it i' ll get none. looks like the fortimail isnt filtering nor processing any emails.
pa
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors