Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

How To Sniff SMTP Traffic Correctly

I' m wana use the command: " diag sniffer packet internal" to get which computer are sending SPAM to internet trough my FG Unit public ip. How can I do that? I need to found which PC is sending spam because my ISP report that my IP address is in an abuse list. Maybe it could be for a kind of virus, but my antivirus said that everything is fine. We do not have internally SMTP server. Thanks in advance,
4 REPLIES 4
red_adair
New Contributor III

#diag sniff pack internal ' tcp and port 25 and not host <ip-of-your-ext-mail-server' so you sniff for all smtp traffic except traffic to/from our ext SMTP Mail Server. As an immediate action - why do you not refuse SMTP except to your external SMTP?
rwpatterson
Valued Contributor III

If you look through the dashboard ' Statistics > Sessions > Details' and filter on destination port 25, you' ll see all traffic going out to SMTP servers. The source should be very clear there. Good luck

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
John_Stoker
New Contributor II

If you do deny all smtp outbound minus your mail server, then you can reference you traffic logs (if " log traffic" is enabled in the policy) to see what IPs are getting blocked for mail. many ways to find this out, but best practice would be to block smtp outbound except where absolutely needed. Best of luck
John CISSP, FCNSP Adv(thanks)ance
John CISSP, FCNSP Adv(thanks)ance

Hi ...I block SMTP outbound trafic to all minus our mail server and then we check our logs. Thanks for your support. Best Regards,
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors