Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rickards
New Contributor

Redirect traffic not using VIP

Hi I have a question regarding redirecting TCP traffic going to mailserver which should be redirected to a antispam system. Currently they reside on the internal network which consists of public ip addresses and in front there is an Fortigate firewall in transparent mode. I wish to redirect traffic coming from external interface to mailserver to antispam system, and only traffic coming to port 25 (smtp) should be redirected. It is possible to change to routing mode and i can change IP subnet for antispam system but i do not wish to move the public ip addresses to VIP' s on the external interface. Topology: INTERNET = WAN1 SERVERS and ANTISPAM = INTERNAL FGT in transparent mode (can be changed..) Currently running FortiOS 4.3.9 but i can upgrade if there has come any new features in later releases.
2 REPLIES 2
PM
New Contributor

Can you change your DNS MX record(s) for your email domain(s) to point to the antispam server instead of the mailserver? Then restrict who can access the mailserver directly from external addresses.
rickards
New Contributor

Hi No that is not possible and also the reason for trying to divert traffic in the firewalls.
Labels
Top Kudoed Authors