Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Policy route for SMTP traffic out

HI, We have a 60b firewall with 1 WAN connection that has a block of 8 IP addresses assigned to it. The IP address being used as the gateway is : 217.155.85.254 We want to use 217.155.85.251 for sending SMTP traffic as there was a bit of a blunder with our mail relay when adding the domains, when we added them it used the IP address the current MX record pointed and automatically added it to the relays allowed list. The issue is that the MX pointed to 217.155.85.251 and our firewall is sending from 217.155.85.254, and being blocked. I' ve raised a ticket with them to add the full range of addresses but wanted to know how to work this out locally on the firewall, as I' m pretty sure it can be done and don' t like being beaten (even though you could consider asking for help being beaten ;)) I tried the following: Setup a policy route; protocol: 6 incoming interface: switch Source address / mask: 192.168.30.0/24 destination address / mask: 0.0.0.0/0.0.0.0 destination ports: from (25) to (25) force traffic to: outgoing interface: WAN1 Gateway address: 217.155.85.251 This broke SMTP out. I read in the manual that its possible to add another address in the same range as the default gateway and it should work. but no. Anyone know how to make this work?
22 REPLIES 22
Not applicable

I always read the notes anyway but its just with someone above saying zones aren' t used in later firmwares that made me think Id have to re create all the policies. I' ll have a read through the notes shortly and give it a go later if it seems ok.
ede_pfau
SuperUser
SuperUser

No, it' s not that zones aren' t available or useful anymore. In later versions of FortiOS you can create ippools without binding to an interface and because of this you can use the pool even with a zone. Maik posted that he couldn' t use zones on external ports because then he wasn' t able to use ippools there, and that is quite common.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

I' ve updated the firewall to MR2 patch 3 now (this is also running on a 110c unit at the main site) and all is good. I prefer the new interface as well. Emails now flowing through the mail relay/scanner for both inbound AND outbound (interestingly just as I got this going, I received a call from Trend Micro IMHS support regarding my request to add the other IP to the allowed list for the mail relay, it seems solutions are like buses and never arrive on their own! ) FSAE updated on DC' s and all is ticking along perfectly. Thanks for the advice guys :)
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors