Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Neophron
New Contributor

Fortimail anti-spam license

Good morning,

Yesterday I've updated Fortimail, to v5.3,build634,170228 (5.3.9 GA ).

Since then there seems to be some extra spam, which could be a coincidence or it could be related to the update.

The thing that worries me is the anti-spam status. the license status looks like this :

AntiSpam:Trial (Expires Unlimited)AntiSpam definition:7.00370 (Updated 2017-07-20)

 

By the looks of it, the anti-spam definition is updated, same goes for AV.

However AV is green, antispam is yellow. is this normal? should I update / renew the license?

Thanks!

1 Solution
Carl_Windsor_FTNT

>Weird that the AV had no issues but the AS needed 53 UDP to be able to operate / go green.

 

This is because AV is based on a signature database downloaded periodically or on push notification over HTTPS.  The AS lookups however are performed in real-time to the FortiGuard DB over UDP/53, 8888 or 8889.  One thing you have to be careful with when using UDP/53 is Cisco's DNS fixup as it will kill the traffic for not being valid DNS.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

View solution in original post

3 REPLIES 3
Neophron
New Contributor

I found the solution. http://kb.fortinet.com/kb/documentLink.do?externalID=FD36662

yesterday I tweaked some ACL's rendering the fortimail AS useless. Weird that the AV had no issues but the AS needed 53 UDP to be able to operate / go green.

Carl_Windsor_FTNT

>Weird that the AV had no issues but the AS needed 53 UDP to be able to operate / go green.

 

This is because AV is based on a signature database downloaded periodically or on push notification over HTTPS.  The AS lookups however are performed in real-time to the FortiGuard DB over UDP/53, 8888 or 8889.  One thing you have to be careful with when using UDP/53 is Cisco's DNS fixup as it will kill the traffic for not being valid DNS.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

Neophron

Thanks for the headsup! I'll adjust the port number :)

Labels
Top Kudoed Authors