Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jeff_Rodgers
New Contributor

Spam where Sender prefix equals Recipient prefix

Using a Fortigate 600C,v4.0,build0521,120313 (MR3 Patch 6) and a fully patched Exchange 2010 SP3 We are receiving a large volume of spam where the Sender Prefix equals the Recipient Prefix. For example, Jeff@mydomain.com is receiving spam from Jeff@anydomain. Is there anyway using the Fortigate to block this junk email? We are getting just bombed with this stuff and most of it is the Penny Stock Image spam variety. Help!
3 REPLIES 3
AndreaSoliva
Contributor III

Hi your request is a little bit based on to less informationer which means: - What are you using on the FortiGate already to prevent such emails (SpamFilter?) If you use NO Spamfilter and you " have FortiGuard" (Service of FGT meaning WebFilter, SpamFilter etc.) licensed you can configure a SpamFilter something like following: config spamfilter profile edit [Name of Profile] set extended-utm-log enable set spam-log enable set spam-filtering enable set options spamfssubmit spamfschksum spamfsurl spamfsip spamfsphish spamrbl spamfsurl config imap set log enable set action tag set tag-type subject spaminfo set tag-msg " SPAM" end config smtp set log enable set action discard set tag-type subject spaminfo set tag-msg " SPAM" set hdrip enable set local-override disable end config pop3 set log enable set action tag set tag-type subject spaminfo set tag-msg " SPAM" end config mapi set log enable set action discard end config msn-hotmail set log enable end config yahoo-mail set log enable end config gmail set log enable end end Addtional to the SpamFilter you can configure addtional DNSBL Servers like something of following (this ones are free of charge): config spamfilter dnsbl edit 1 set name spamhaus set comment spamhaus.org config entries edit 1 set action spam set server zen.spamhaus.org set status enable end end config spamfilter dnsbl edit 2 set name spamcop set comment spamcomp.net config entries edit 1 set action spam set server bl.spamcop.net set status enable end end This should prevent the spam' s which means check afterwards the spamfilter itself which means over the gui: Security Profiles > Email Filter > Profiles > [Name of your Profile] If you have enauch performance on the FGT you can enable all Positions based on " FortiGuard Spam Filtering" . This positions are covering (INBOUND) connections. The positions under " Local Spam Filtering" are covering (OUTBOUND) connections which normal is not activated but in case of kee an eye on the position " HELO DNS Lookup" which means if you are activating this position you have to be careful that for every device sending emails to outside world a A, MX as a Reverse Lookup is existing within internal DNS server. If this is not the case the mails will be blockt on the FGT. This SpamFilter has a good quality but is not equal FortiMail or/and Ironport. Under normal circumstances you will get a good result. After you created the Profile use this profile together with the proxy options within the Policy you are covering the Inbound SMTP connection. Keep in mind that if you use SMTP you can use this kind of the art to use SpamFilter on a FGT. If you use some protocolls which are encrypted like SMTPS you are not able to use out of the box this kind of the aret SpamFilter. Hope this helps. have fun Andrea
Dipen
New Contributor III

Hi have you checked the E-mailheaders of these Spam mails to check the Originating IPs. You can create a manual blacklist and add it to your Anti-Spam Policy. Please ensure you have Anti-Spam UTM configured in Place.

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
Osama_Shatnawi
New Contributor

Hi You have to enable spam filtering and use the different techniques available there like checksum, spam submission, sender IP and other techniques.
Using a Fortigate 600C,v4.0,build0521,120313 (MR3 Patch 6) and a fully patched Exchange 2010 SP3 We are receiving a large volume of spam where the Sender Prefix equals the Recipient Prefix. For example, Jeff@mydomain.com is receiving spam from Jeff@anydomain. Is there anyway using the Fortigate to block this junk email? We are getting just bombed with this stuff and most of it is the Penny Stock Image spam variety. Help!   Rate this post! Date: 4/11/2014 9:28:52 AM AndreaSoliva Silver Member   Posts: 103 Score: 15 Joined: 2/10/2014   RE: Spam where Sender prefix equals ... (in reply to Jeff Rodgers)  Hi your request is a little bit based on to less informationer which means: - What are you using on the FortiGate already to prevent such emails (SpamFilter?) If you use NO Spamfilter and you " have FortiGuard" (Service of FGT meaning WebFilter, SpamFilter etc.) licensed you can configure a SpamFilter something like following: config spamfilter profile edit [Name of Profile] set extended-utm-log enable set spam-log enable set spam-filtering enable set options spamfssubmit spamfschksum spamfsurl spamfsip spamfsphish spamrbl spamfsurl config imap set log enable set action tag set tag-type subject spaminfo set tag-msg " SPAM" end config smtp set log enable set action discard set tag-type subject spaminfo set tag-msg " SPAM" set hdrip enable set local-override disable end config pop3 set log enable set action tag set tag-type subject spaminfo set tag-msg " SPAM" end config mapi set log enable set action discard end config msn-hotmail set log enable end config yahoo-mail set log enable end config gmail set log enable end end Addtional to the SpamFilter you can configure addtional DNSBL Servers like something of following (this ones are free of charge): config spamfilter dnsbl edit 1 set name spamhaus set comment spamhaus.org config entries edit 1 set action spam set server zen.spamhaus.org set status enable end end config spamfilter dnsbl edit 2 set name spamcop set comment spamcomp.net config entries edit 1 set action spam set server bl.spamcop.net set status enable end

Osama

Osama
Labels
Top Kudoed Authors