Hi All,
I have experience with a number of Forti roducts but Fortimail is completely new to me.
I am deploying a solution replacing the embedded mail protection on some Sophos XGs.
I have the Fortimail up but I am unusure how I can replicate and route traffic.
The Sophos only has two policies in the mail configuration. The first is allow mail to the domain recipient and scan this mail - this is not used as mail accounts are in O365. The second is allow mail from internal servers to internal users (in O365). Mail sent from named servers to a named relay and then on to the mail account. An exception rule was created allowing either the host source or sender address to skip AV/Spam etc checks and send through the mail and out to O365 whilst checking all other mail.
I have set configured the domain for the mail FQDN in Domain User>Domain configuring relay type MX Record. I have also configured a recipient policy for recipients of the mail domain. The Fortimail will sit between (on the internal VRF) the user and server lan and the Fortigate edge.
Here I am lost - how do I replicate the policies for second Sophos policy and how do I set the routing of the mail from server to Fortimail and mail to O365?
Apologies for simple questions and fact I may be majorly overthinking but this will help me open my eyes.
Thanks in Advance
Adrian
Hello southside,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello Adrian,
I found this solution, can you tell me if it helped?
To replicate the Sophos policy and set up mail routing from the server to FortiMail and then to Office 365, follow these steps:
By following these steps, you should be able to replicate the Sophos policy and ensure proper mail routing through FortiMail to Office 365.
Hello Adrian
If I understand well your case (I'm not sure I do 100%), you just need your internal servers to send e-mails via o365, right?
If this is the case then I'm not sure you need a FortiMail for that. You just need your servers to be configured to send mails via o365.
Or am I misunderstanding your requirement?
Great thread and super helpful to read through! I'm also starting to work with FortiMail and found the process of replicating existing mail policies surprisingly tricky at first. The detailed breakdown about setting up relay rules, exception handling, and Office 365 connectors really cleared up a lot of my confusion. It's easy to overthink it when you're used to other platforms, but it’s good to know that with the right routing profiles and access rules, FortiMail can handle this cleanly. Thanks everyone for the guidance — feeling a lot more confident about my deployment now!
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.