Hi,
(Fortigate 201F, 7.4.3)
I have a new SD-WAN setting, and I have an internal e-mail server. How can I limit the email server traffic (SMTP) so that traffic only goes out through the designated SD-WAN interface. If that interfece go down, I do not want to allow to go this traffic out in other SD-WAN interface.
A would like to prevent the email traffic to go out from an other public IP. My current goal is not to configure the mail server (DNS, MX, SPF etc...)
I tried to create an SD-WAN rule (Interface selection strategy = Manual) with the mail server address and SMTP traffic, where I only specify one SD-WAN interface in the interface preferences, but it seems that if I stop this interface, the traffic still starts to go out on the other interface. How can I stop this from happening?
Thanks
To ensure that email (SMTP) traffic only exits through the designated SD-WAN interface and doesn't failover to another interface, you can use a combination of SD-WAN rules and firewall policies. First, create an SD-WAN rule with the Manual interface selection strategy, specifying the correct SD-WAN interface for your email server’s IP and SMTP traffic. Then, set up a custom firewall policy to match the email server’s traffic and apply a deny rule for other interfaces. Additionally, disable SD-WAN failover for that specific rule by configuring the Failover option to Disable. This will prevent the SMTP traffic from being routed through any other interface if the designated one fails. I did the same practice at http://thevapetown.com/vape-shop-in-islamabad/
You can create 2 sdwan zone and place each interface in separate zone and create 2 firewall policy with 2 zone and on the 2nd zone set the action as deny
Hi @fortinetforumfiokom ,
One solution would be to create a policy route for this traffic.
Policy route has higher priority than SD WAN rule so the traffic would follow the Policy route you create.
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/144044/policy-routes
Regards,
Varun
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.