Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Issue allowing SMTP in.

outbound is fine but have issues with inbound. Have a firewall policy for ISP-mail to trusted exchange 2010 server but when looking at logs on ISP mail server connection to x.x.x.x:25 times out after 15 seconds and email sent to re-try que.
35 REPLIES 35
ede_pfau
SuperUser
SuperUser

Welcome to the forums. A little bit more information would help a lot. How have you configured the access to the internal mail server? Can you post the firewall policy (and everything related, i.e. the VIP definition), please?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

Thanks for the relpy, am very new to Fortigate' s and do not have any VIP' s Can send email out no problem. for mail server access in i have firewall policy: wan1 - mailserver IP/subnet to switch - ip/sub of exchange smtp accept hope that helps ?
ede_pfau
SuperUser
SuperUser

Oh, I see. As you are new to this I won' t tell you what is wrong but show you how to make it work. Say, your external (public) IP that stands for your mailserver is 80.80.80.1. - Be aware that it will be " used up" by the configuration below, i.e. it should be available exclusively for your mailserver. And the real server in your LAN hosting Exchange has the 192.168.10.10. Then you take 2 steps: - define a Virtual IP (Firewall>VIP) to make the FG translate the external IP to your internal IP, just for this server: Create New>give it a decent name e.g. " ExchangeVIP" , external IP=80.80.80.1, mapped to IP=192.168.10.10, no further checks. - delete the policy external->internal already in place. - define a firewall policy using this translation: Create New>from: external, source=all, to: internal, destination:ExchangeVIP, service=SMTP Now you should be able to ping the external IP and receive a reply from the Exchange server. If that works please come back and we' ll refine the setup.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

Thanks again, i need do have to enter 25 in the service port and map to port ? Have done all requested but email is still not comming in. are there further steps now ? isp email log still timing out connecxtion to mt wan1 ip on port 25 cheers
ede_pfau
SuperUser
SuperUser

No, at the moment you should leave the port settings empty and the " Port Forwarding" box un-checked. Have you tried to ping your external mailserver IP?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

yes but i know for a fact it does not respond to pings so do not get a reply. any other tests ??
ede_pfau
SuperUser
SuperUser

I' m afraid I need more information on what is configured and what not. The setup itself is quite simple so it should work right away. You can backup the config to a file, in plain text format. Please post the part named " config firewall" up to the final " end" , or upload the config file itself. In the meantime, why would the server not respond to ping? Is there a software firewall installed on it which might not only block ping but incoming SMTP also?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

ok here is the file
ede_pfau
SuperUser
SuperUser

Thanks. You can edit your last post and delete the attachment now. OK, I see you have defined policy routing from the external IP to the Exchange server' s IP. Delete that please. Then, in policy 8 add " ping" to the service allowed, or select " Any" . I would strongly advise you to specify IP addresses in the address definitions, not subnets. You do so by writing " 1.2.3.4/32" for a single host address. Please test pinging the server now.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors