Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NeoRant
Contributor

Fortimail False positives

Hi Guys, 

 

I am grateful for this community, some great teachers here, I am learning alot about Fortimail and have done some good work so far.

 

I have now fully integrated my fortimail in the DMZ, the fortigate fwl, getting smtp traffic, inspection of smtp traffic actually WORKING, thank God.

 

However, one problem lol. ALOT of false positives and people are squealing. I used the full inspection rules instructed by guide below - antispam, antivirus, content etc and I tell you mails are being inspected hard.

https://ebin.pub/fortinet-fortimail-lab-guide-for-fortimail-72.html

 

Can anyone here post me a good setup for traffic inspection (not so robust/sensitive)?

 

I am currently using the recipient policy as that is what was selected by my team. I was the one that configured the fortimail from scratch and deployed it(with the help/knowledge of you guys of course).

11 REPLIES 11
AEK

@Cajuntank, I never used DNSBL as in my experience FortiGuard (IP Reputation) is best quality and gives much less false positives.

AEK
AEK
Cajuntank
Contributor II

I get that. My thought process on the matter; with the short amount of time I have had the product in production mind you, is I feel better knowing I am not "putting all of my eggs in one basket" for that determination balanced with not going overboard with that logic.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors