Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Issue allowing SMTP in.

outbound is fine but have issues with inbound. Have a firewall policy for ISP-mail to trusted exchange 2010 server but when looking at logs on ISP mail server connection to x.x.x.x:25 times out after 15 seconds and email sent to re-try que.
35 REPLIES 35
ede_pfau
SuperUser
SuperUser

well I mean, friend or no friend, you can' t suck up the traffic for _his_ mailserver' s IP into _your_ LAN, can you? so, please be sure that the IP you choose is belonging to you and not used anywhere else - not for your router, nor firewall. From the config file I see you have a small net of external IPs, xxx.101.65.193...198. .196 is used by the firewall. .193 is your default gateway -- your ISP' s router? (or just a typo?) .194 answeres to ping so it' s used. your choice. Put this IP into the VIP definition for " EXCHANGE_VIRTUAL" . And test, first with ping and then with telnet to port 25.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

ok it will be 197 just to clarify one thing the ISP mail server is set to forward my email to my wan address assume this makes no difference. will carry on with previuos post.....
Not applicable

done that but can' t ping .197
Not applicable

cna ping 197 now (had chnaged service back to smtp will leave at any until end now )
ede_pfau

[sorry had to work...] I see you' re learning fast... so letz try with SMTP... 421 4.3.2 Service not available seems routing finally is working, now what' s wrong with Exchange?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

i assume exchnage is not your bag and for this forum. but that is where i should be looking now. have receive connector so should set this for .197 now
Maik
New Contributor II

have receive connector so should set this for .197 now
.197 is now your exchange server/destination. the receiver connector should be set to the sources you want to receive mails. E.g. your ISP' s mailserver or 0.0.0.0 255.255.255.255 in case you go with the " MX" variant.
ede_pfau

just to clarify one thing the ISP mail server is set to forward my email to my wan address assume this makes no difference.
nope, the mail has to be forwarded to .197! The Fortigate cannot handle mail... Apart from that, you should be able to telnet to .197 and get Exchange on the line. When your server is finally available you would set your domain' s MX record to this public IP.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

am still here will keep checking / updating
ede_pfau

looks promising: 220 ERNIE.ukgroup.xxxx.co.uk Microsoft ESMTP MAIL Service ready at Mon, 27 Sep 2010 17:24:04 +0100 250-ERNIE.ukgroup.xxxx.co.uk Hello [91.17.133.176] Do you see mail at the end of the tunnel?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors