Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
micahawitt
New Contributor III

Spam Policy match

I am currently using a FM-VM, running 5.2.2.

 

I have set my policies to discard E-mails that are Fortiguard and SURBL using zen.spamhaus.org since i meet the "Free Use" technicality that the specify.

 

Currently, nothing incoming is getting rejected via Fortiguard or the Zen list, all SPAM is getting thrown into quarantine, which yes is ultimate goal, however, if it should not even hit the mail system, i would like my Forti-mail to outright get rid of it, what am i missing here?

 

Thank you

 

Micah

7 REPLIES 7
emnoc
Esteemed Contributor III

In your actions, what do you have checked?

 

[I

Discard? System quarantie?    .......E.g

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
micahawitt
New Contributor III

Em,

 

I have the screenshot attached that shows the options checked.

 

Thank you

emnoc
Esteemed Contributor III

I sorry for the confusion, in your set  "discard_inbound" action. what do you have set? I only see your AS profile.

antispam > action

 

This and any default action is what takes place for your AS checks.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
micahawitt
New Contributor III

Emnoc,

 

In the discard action profile, the only option that is checked is to simply discard, I would think that even though it is discarding, it would still show as a "hit" to the system and mark it in the system as a SPAM, or whatever it is classified as.

 

I have attached another screen shot.  And I guess what I am trying to figure out is that a lot of these are SPAM, yes they are simply going to quarantine, it seems the system is not doing spamhaus checks or fortiguard checks for something that it should.

 

Thank you

 

Micah

micahawitt
New Contributor III

I think I may have figured something out.

 

I created a new AS inbound profile, and I did it based on the domain incoming and not using the default system incoming profile and it seems that things are picking up as they should in the logs.  Meaning if it is a Fortiguard reject, it logs it as such and discards.

 

I will monitor and post back if there is any other confusion, thanks for all the help!

emnoc
Esteemed Contributor III

I'm glad it all worked out. I didn't notice that "system" until I read your last post. I think systems should imply all domains, but I never built a policy "using just systems" . Keep monitoring your logs & system quarantine for any changes.

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
micahawitt
New Contributor III

Yea,

 

I built my initial profile based on a clone and tweaked from there.

 

I think doing the granular based on the actual incoming domains is working better.

 

Micah

Labels
Top Kudoed Authors