FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
pchee
Staff
Staff
Article Id 313250
Description This article describes how to disable FortiMail from offering STARTTLS.
Scope FortiMail
Solution
  1. Test the connection from [FortiMail Gateway] acting as an MTA and it is possible to see that FortiMail offers STARTTLS in the initial EHLO:

 

Offer.jpg

 

  1. Go to the target receiving host, in this case, it will be [FortiMail Server mode].
  2. Go under Policy -> Access Control -> Receiving.
  3. Create a new Policy that defines the source IP and Recipient pattern.

 

ACR.jpg

 

  1. Under the TLS Profile, create a new TLS profile namely NO_STARTTLS with the TLS Option set to NONE.

 

none.jpg

 

  1. When performing a second test connection from [FortiMail Gateway], the result no longer offers STARTTLS in the initial connection.

 

nooffer.jpg

Contributors