I have what I thought was a very simple setup and of course it is not though from everything I have read it would seem that I have everything setup appropriately.
I am evaluating a cloud-based Email Security Service. I have 2 Fortigate 80Cs, setup in HA Cluster in NAT operation mode.
All I want to happen is the following: When anything comes in over SMTP protocol from ONLY a particular subnet, it then forwards it to my email server directly (to be permanent). When anything comes in over SMTP protocol NOT from this subnet, I want to be forwarded over to my current security appliance on site.
There are 2 problems I am having with the Virtual IP Setup.
1.) When I try to create 2 rules that both forward port 25 but to different places, depending on the incoming address, I get " A Duplicate Entry Already Exists Error" . Now I understand in theory it would get confused if I simply had 2 different places to send SMTP traffic. However, if I delineate depending on the INCOMING address and set the policy order properly why would this not work?
2.) I am confused as to how I would delineate the from address. Currently, the only way I can get it to work is by setting an Address as the Subnet of the remote service. Then create a policy that uses that address as the source address on my WAN port. However, on my Virtual IP, I am unable to set the proper External IP Address/Range to the subnet of the hosted service. The reason is because when I do that and then try to specify only my email server as the mapped IP Address, it automatically creates an inappropriate ending address. I have uploaded the image to show what I mean.
It automatically creates the 201.20.96.21 ending IP, which is not correct. It should be 255.255.255.255.
Perhaps I am thinking about this the wrong way, but I really need to get this working ASAP. Thanks.
Mike