Hi! I have problem with my smtp server. I need to migrate my service from box Linux to Fortigate 100E. In this moments i can to access to ports 25 and 465 using Virtual IP. My problem is when the emails get out to a external service. For this i am using IP Pool for using specific external IP and it works but the communication never finishes. Sniffering some traffic a i realized that the source port changes at the moment of comunication over port tcp-25 which is not the case with the port tcp-465. The Policy for output traffic using the IP Pool is the same for twice ports from the internal IP.
[ul]I attach one image with the traffic.
Could guide me in solving the problem?
can you please share the VIP and firewall-config?
Can you highlight what you think is the issue in the screenshot?
You mentioned source-port change, but that remains 34990 throughout the handshake. Nothing wrong there, the session even ends cleanly with a FIN-ACK exchange.
The random SYN-ACKs to port 31179 are most likely either unrelated, or malicious(?).
Suggestion:
Check if the traffic flowing through this policy is offloaded. The pattern of packets that we see for the session between ports 34990<->25 (I'm too lazy to write out the IPs, sorry) matches a typical pattern of a session offloaded to NP:
1, TCP handshake visible (not offloaded, unless doing hyperscale on NP7)
2, further traffic offloaded (not seen in pcap, assuming no UTM inspection)
3, FIN-ACK exchange visible in pcap again (any session-closing/interrupting FIN/RST packets gets sent to the kernel again, making it visible in pcaps)
If you're having problems with the traffic, you will need to ensure that offload is disabled, otherwise you won't get a full picture in your packet captures.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1744 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.