I am currently using a FM-VM, running 5.2.2.
I have set my policies to discard E-mails that are Fortiguard and SURBL using zen.spamhaus.org since i meet the "Free Use" technicality that the specify.
Currently, nothing incoming is getting rejected via Fortiguard or the Zen list, all SPAM is getting thrown into quarantine, which yes is ultimate goal, however, if it should not even hit the mail system, i would like my Forti-mail to outright get rid of it, what am i missing here?
Thank you
Micah
In your actions, what do you have checked?
[I
Discard? System quarantie? .......E.g
PCNSE
NSE
StrongSwan
Em,
I have the screenshot attached that shows the options checked.
Thank you
I sorry for the confusion, in your set "discard_inbound" action. what do you have set? I only see your AS profile.
antispam > action
This and any default action is what takes place for your AS checks.
PCNSE
NSE
StrongSwan
Emnoc,
In the discard action profile, the only option that is checked is to simply discard, I would think that even though it is discarding, it would still show as a "hit" to the system and mark it in the system as a SPAM, or whatever it is classified as.
I have attached another screen shot. And I guess what I am trying to figure out is that a lot of these are SPAM, yes they are simply going to quarantine, it seems the system is not doing spamhaus checks or fortiguard checks for something that it should.
Thank you
Micah
I think I may have figured something out.
I created a new AS inbound profile, and I did it based on the domain incoming and not using the default system incoming profile and it seems that things are picking up as they should in the logs. Meaning if it is a Fortiguard reject, it logs it as such and discards.
I will monitor and post back if there is any other confusion, thanks for all the help!
I'm glad it all worked out. I didn't notice that "system" until I read your last post. I think systems should imply all domains, but I never built a policy "using just systems" . Keep monitoring your logs & system quarantine for any changes.
Ken
PCNSE
NSE
StrongSwan
Yea,
I built my initial profile based on a clone and tweaked from there.
I think doing the granular based on the actual incoming domains is working better.
Micah
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.