Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bachri_faisal
New Contributor

HELP!! STARTTLS/SMTPS error: connect failed=-1

Hi, After succesfully upgrade firmware from v4 MR3 Patch 1 to Patch 5, Fortimail can not relay email to Protected domain (internal email server). There an error message on email logs as follow. When SMTPS enabled, error message will be as follow: from=test@example.com, size=0, class=0, nrcpts=1, proto=SMTP, daemon=SMTP_MTA, relay=[xxx.xxx.xxx.xxx] from=test@example.com, size=88, class=0, nrcpts=1, msgid=<201305240412.r4O4CROY005339-r4O4CROb005339@xxxx-xxxx>, proto=SMTP, daemon=SMTP_MTA, relay=[xxx.xxx.xxx.xxx] SMTPS=client, error: connect failed=-1, SSL_error=1, errno=0, retry=-1 to=xxx@xxx.xxx, delay=00:00:01, xdelay=00:00:01, mailer=esmtp, pri=31574, relay=xxxx.xx.xx. [xxx.xxx.xxx.xxx], dsn=2.0.0,stat=Sent When SMTPS disabled, error message will be as follow: from=test@example.com, size=0, class=0, nrcpts=1, proto=SMTP, daemon=SMTP_MTA, relay=[xxx.xxx.xxx.xxx] from=test@example.com, size=88, class=0, nrcpts=1, msgid=<201305240420.r4O4K4db005565-r4O4K4de005565@xxx-xxx>, proto=SMTP, daemon=SMTP_MTA, relay=[xxx.xxx.xxx.xxx] STARTTLS=client, error: connect failed=-1, SSL_error=1, errno=0, retry=-1 to=xxx@xxxx.xxx, delay=00:00:06, xdelay=00:00:05, mailer=esmtp, pri=31574, relay=xxxx.xx.xx. [xxx.xxx.xxx.xxx], dsn=4.0.0, stat=Deferred: 403 4.7.0 TLS handshake. How to solve this problem? Thanks for any help. Cheers, Faisal
10 REPLIES 10
ajmind

This is really annoying! with v4 MR3 Patch Patch 5 the TLS behaviour was changed:
TLS 1.1 and 1.2 support Started to support newer TLS versions in protocols such as SMTP(S), IMAP(S), POP3(S), HTTPS, and LDAPS for improved security.
We do not need any specific delivery policies as we use our 100C as a gateway to the internet, behind Fortigate 60C and only as a forwarding mail system for our internal exchange servers. so no users are logging into that unit. Any advise were and how to modify the new patch 5 behaviour? Ajmind
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors