Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Issue allowing SMTP in.

outbound is fine but have issues with inbound. Have a firewall policy for ISP-mail to trusted exchange 2010 server but when looking at logs on ISP mail server connection to x.x.x.x:25 times out after 15 seconds and email sent to re-try que.
35 REPLIES 35
Not applicable

well what do you know it pings !!!! What next :)
ede_pfau
SuperUser
SuperUser

Fine. Now you can try to receive email. --- policy 7 is to be changed now. In the form with " Exchange_Server" denoting your whole internal LAN it allows SMTP out from every host on your LAN. You shouldn' t allow that, hosts mail to your mailserver and the mailserver is the only host that can SMTP out. This way, no spam bot on your PCs can mail out. Please change the destination to ALL in policy 7. Your own WAN IP range doesn' t make sense there. ---- policy 9 is not going to work.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

ok we will test now. 2 queries from last post 1 - i do not have a policy 9 listed 2 - policy 7 points from exchange to external ip of isp not my wan i think this is correct ? have now chnaged subnemts to single ip' s
ede_pfau
SuperUser
SuperUser

1 - i do not have a policy 9 listed
well policy 9 cares for Terminal_Services from internal to external. If you have deleted a policy the IDs may change.
2 - policy 7 points from exchange to external ip of isp not my wan i think this is correct ?
Only if the external mailserver is in the " Keystage" network. Is it? You can enable a protection profile for this policy later.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

ok have deleted TS policy. Keystage is where mailserver is. Just tested again but still getting: Route slip host: My wan ip Route slip Port : 25 attempting socket connection to: my wan ip attempting socket connection to: my wan ip:25 waiting for socket connection 15 second wait for connection timeout exceeded Any clues ? Andy
ede_pfau
SuperUser
SuperUser

please clarify this for me: if I telnet to the VIP it connects me to a mailserver, running MDaemon 11.0.2. It calls itself after the domain key...uk Is that your internal mailserver or someone else' s? try for yourself: " telnet ext_ip 25"
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

it' s someone elses mailserver that we get our mail from does that make sence ?
Not applicable

and it is running MDaemon
ede_pfau
SuperUser
SuperUser

whoa... messing around with your ISP' s mailserver IP...they' re not gonna like it! now, what IP do you want to use for YOUR mailserver in YOUR LAN? pick one of the /29 range of wan1, i.e. 185...190.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

ISP owner is a friend so have full access to the server. Anyway if what you are proposing is a better way then i have an ip i can use in my wan range so let' s go for it. poised ready for action Andy
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors