Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JohnnyRedMan
New Contributor

IMAPS and POP3S filtering

Hello, I have users in my LAN that configures their gmail accounts in Outlook. Some use Pop3s and some Imaps (secure only). Can I use fortimail to proxy their traffic although its encrypted and filter incoming attachments and message size? also scan the content with anti virus? Thanks Johnny
6 REPLIES 6
emnoc
Esteemed Contributor III

yes you can. What mode are you currently running now server/gw/transparent? Wth SMTP-Auth you could provide a means for your clients to relay thru the fortimail to any destinations. Also, just for clarifty POPs/IMAPs are client delivery aka MDA and not MTA. Even tho your clients ( outlook ) are receiving mail via gmail, they have a function of using a MTA for delivery.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
JohnnyRedMan
New Contributor

Hey, I still havent purchased the product, just checking if it could provide me of what i need. as i see it, i can install FortiMail as a gateway proxy (server mode), my clients who uses outlook will config their gmail mail boxes in outlook in Imap secure or pop3 secure for receiving emails, encrypted mode only, and the fortimail will proxy their secure connection to gmail and will drop attachment and filter message size including scan the mail for viruses? thanks Johnny
Bromont_FTNT
Staff
Staff

If Outlook is configured with the GMail (IMAPs/POP3s) then it will be a direct connection to the GMail servers on 993/995 and 465 for outgoing, the Fortigate could be configured to do SSL inspection in that case. I don' t see a good fit for the Fortimail here.
emnoc
Esteemed Contributor III

So are you trying to drop attachments inbound or outbound? This is a very strict requirement and I wonder now on how easily that could be bypass ( encryption maybe ) :)

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
JohnnyRedMan
New Contributor

Hey, I will try to explain my self again. I have users with normal PC' s in my Lan, they have outlook installed and their gmail mailboxes configured in that. All setup in Imaps or pop3s (SSL only). I don' t have an internal mail server or a domain or MTA. Just users in the lan and a firewall. What I want is to intercept the SSL connection to gmail and filter incoming mails, drop certain attachments and filter spam. I want to filter it only when they receive emails to their gmail (configured in outlook). I don' t care about the mails they send. Is this kind of requirement can be done using fortimail? And how? I now have a fortimail VM in my lab for test, not sure how to set it up I know it can be done on webmails ( https ) not sure why not on pop3s and I maps....
emnoc
Esteemed Contributor III

If you have google as you corporate email, you might have something even better & right at your finger tips :) https://support.google.com/a/answer/2364580?hl=en A fortimail appliance, would not be the solution that you want , nor with achieving what your looking for btw.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors