I have a mail server on an external IP address and fortigate blocks the address almost every day and messages cannot be sent or received. The mail server then works normally. Was created a policy on the firewall does not help, still the address is blocked. Is it possible to unblock this address so that the router does not block it at all?
Hello,
Do you have any log saying why it is blocked? Is it blocked because of some database, dos-policy, etc?
I looked but could not find in the logs. There is no policy to block it. Router blocks it has about 30 min then it starts working again.
Hi Tness
May I know how the users are trying to access the mail server?
Are they using SSL VPN to access the mail server or have you configured a Port forwarding to access the mail server in the network
Assuming that it is port forwarding that you have configured on the firewall. You could run the below command to check which policy the traffic is hitting
di de reset
di de flow filter saddr x.x.x.x
di de flow filter daddr y.y.y.y
di de flow show function-name en
di de flow show iprope en
di de flow trace start 1000
di de en
The mail server is off-network hosted by another company. Users connect to it via Outlook and send and receive messages from there, they do not use a VPN and there are no port forwarding configured
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.