Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ultimo
New Contributor

How to configure EMAIL filter with external Exchange server

Greetings,

 

I have a Fortigate 70D behind a firewall in transparent mode. URL filtering is working ok and blocking bad sites.

I have configured the mail filter as in sshot. I have an external Exchange server that is connecting over.

 

But the emails with SPAM are still getting trough. I have addedd the filter to both policy traffics 

internal-wan1

wan1-internal

 

Has anyone some idea and similar setup?

 

Thanks in advance.

4 REPLIES 4
m_raza
New Contributor

Proxy base inspection mode is much better & efficient than flow base.

Baptiste

If you have an external Exchange server, e-mails are not going thru your FW, they are directly send/receive from it.

Your FW will only see client/server traffic (Outlook/OWA)

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
rh1
New Contributor

Hi,

i'm not so familiar with spam filtering but i've setup the similar environment once before, and it worked.

my policy was something like the below.

 

/*-----

set schedule "always" set service "POP3" "IMAP" set av-profile "spam-av" set spamfilter-profile "spam" set nat enable

-----*/

 

basically, what i did was create a new policy that allows POP and IMAP, and apply the filters(filters was set in proxy mode).

 

you might want to check if your clients use POP3 or IMAP(non ssl/tls version).

 

hope this would help

Carl_Wallmark
Valued Contributor

Enable external RBL servers to your profile for higher catch rate:

 

http://kb.fortinet.com/kb...ateId=0%200%2086179855

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Labels
Top Kudoed Authors