Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
h_celik
New Contributor II

Same domain Outbreak-protection delay

Hello,
We have a hybrid configuration on our domain. When we receive mail from our M365 mailboxes to our on-prem exchange mailboxes, the mail is classified as fortiguard spam outbreak. We has opened a case. Tac engineer gave the following suggestion;
1) Change the level from 'High' to 'Medium'.
2) Place the domain or sender IP in the Safe list (it will bypass the entire AntiSpam profile).
3) Create a specific Recipient policy with the AntiSpam profile where FortiGuard Spam outbreak protection is disabled.
4) Set the spam outbreak protection time to minimum (6 minutes).

I wonder if I change the outbreak protection level to low or medium, how will this affect us?

Regards

Regards
2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Celik

The default value is medium.

I always find the default values in FML the best values for most usage, and I usually don't change default value except if I know what I'm doing.

Medium or low means less mail types will be deferred for outbreak.

Ref:  https://docs.fortinet.com/document/fortimail/7.6.0/cli-reference/18342/system-fortiguard-antispam

 

 

AEK
AEK
h_celik
New Contributor II

Hello,

I changed high to medium, and I'll monitor logs this week

 

Thanks, sincerely

Regards

Regards
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors