- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortimail deployment questions
Hi All,
I have experience with a number of Forti roducts but Fortimail is completely new to me.
I am deploying a solution replacing the embedded mail protection on some Sophos XGs.
I have the Fortimail up but I am unusure how I can replicate and route traffic.
The Sophos only has two policies in the mail configuration. The first is allow mail to the domain recipient and scan this mail - this is not used as mail accounts are in O365. The second is allow mail from internal servers to internal users (in O365). Mail sent from named servers to a named relay and then on to the mail account. An exception rule was created allowing either the host source or sender address to skip AV/Spam etc checks and send through the mail and out to O365 whilst checking all other mail.
I have set configured the domain for the mail FQDN in Domain User>Domain configuring relay type MX Record. I have also configured a recipient policy for recipients of the mail domain. The Fortimail will sit between (on the internal VRF) the user and server lan and the Fortigate edge.
Here I am lost - how do I replicate the policies for second Sophos policy and how do I set the routing of the mail from server to Fortimail and mail to O365?
Apologies for simple questions and fact I may be majorly overthinking but this will help me open my eyes.
Thanks in Advance
Adrian
- Labels:
-
FortiMail
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello southside,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Adrian,
I found this solution, can you tell me if it helped?
To replicate the Sophos policy and set up mail routing from the server to FortiMail and then to Office 365, follow these steps:
- Configure FortiMail to Relay Emails:
- Ensure that FortiMail is configured to relay emails from your internal servers to Office 365.
- Go to `Profile -> Session` and select the session profile being used.
- Under `Advanced Control`, create a new `Mail Routing` profile to specify the relay path. - Set Up Recipient Policies: You have already configured a recipient policy for the mail domain. Ensure that this policy allows emails from internal servers to be processed correctly.
- Create Exception Rules:
- To replicate the exception rule from Sophos, create a policy in FortiMail that allows emails from specific internal servers or sender addresses to bypass AV/spam checks.
- Go to `Policy -> Access Control` and create a new policy that matches the source IP or sender address and sets the action to allow without scanning. - Configure Mail Routing:
- For routing mail from the server to FortiMail, ensure that the internal servers are configured to use FortiMail as their SMTP relay.
- In FortiMail, configure the mail routing to forward emails to Office 365. This can be done by setting up a connector in Office 365 to accept emails from FortiMail. - Office 365 Configuration: In Office 365, ensure that a connector is set up to accept emails from FortiMail. This involves configuring the mail flow rules to accept emails from FortiMail's IP address.
- Testing: Test the configuration by sending emails from the internal servers and verifying that they are correctly routed through FortiMail to Office 365.
By following these steps, you should be able to replicate the Sophos policy and ensure proper mail routing through FortiMail to Office 365.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Adrian
If I understand well your case (I'm not sure I do 100%), you just need your internal servers to send e-mails via o365, right?
If this is the case then I'm not sure you need a FortiMail for that. You just need your servers to be configured to send mails via o365.
Or am I misunderstanding your requirement?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Great thread and super helpful to read through! I'm also starting to work with FortiMail and found the process of replicating existing mail policies surprisingly tricky at first. The detailed breakdown about setting up relay rules, exception handling, and Office 365 connectors really cleared up a lot of my confusion. It's easy to overthink it when you're used to other platforms, but it’s good to know that with the right routing profiles and access rules, FortiMail can handle this cleanly. Thanks everyone for the guidance — feeling a lot more confident about my deployment now!
