Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aszypula
New Contributor

Fortimail & address mapping & LDAP

Hello, [sorry for my English :)] I need help with Fortimail (I have a problem with proper configuration of Fortimail unit) [Fortimail-VM MR3p1] I have a domain domain.com, and account aszypula@domain.com (LDAP). When I trying to send email from aszypula@domain.com to non-existent email account (eg alalalalalalalalala1221al12@gmail.com), aszypula@domain.com don’t receive any error message, instead of this an error message lands in Dead Mail folder. This message has fields: To: - empty field From: postmaster <postmaster@domain.com> When I send email to an existing email account everyfing is OK (recipient recive message). Looks like Fortimail (postmaster) „can’t see” LDAP users/alias to deliver error messages. Is any way to resolve issue? What am I doing wrong? I have similar problem with alert account. I create alert account eg alert@domain.com. I create LDAP alias between alert@domain.com|---->aszypula@domain.com (LDAP). When I test alert account, I recive error message:
 The original message was received at Sat, 26 May 2012 23:35:29 +0200
 from:
 <>
 with id q4QLZTfT003888-q4QLZTfT003888
 
    ----- The following addresses had permanent fatal errors -----
 alert@domain.com
     (reason: 550 5.1.1 User unknown)
 
    ----- Transcript of session follows -----
 550 5.1.1 User unknown
 550 5.1.1 User unknown
When I test alias query in LDAP Profile I receive: Connected to LDAP server Bind with bind DN and password successful Found mail alias 1: aszypula@domain.com Event logs:
 STARTTLS=server, relay=[x.x.x.x], version=TLSv1, verify=NO, cipher=AES128-SHA, bits=128/128
 
 AUTH=server, relay=[x.x.x.x], authid=aszypula@domain.com, mech=LOGIN, bits=0
 
 from=<aszypula@domain.com>, size=2504, class=0, nrcpts=1, msgid=<004701cd3b8c$d6ff53d0$84fdfb70$@domain.com>, proto=ESMTP, daemon=SMTP_MTA, relay=[x.x.x.x]
 
 STARTTLS=client, relay=gmail-smtp-in.l.google.com., version=TLSv1, verify=CAFAIL, cipher=AES128-SHA, bits=128/128
 
 STARTTLS=client, cert-subject=/C=US/ST=California/L=Mountain View/O=Google Inc/CN=mx.google.com, cert-issuer=/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=Certificate Authority/CN=FortiGate CA/emailAddress=support@fortinet.com, verifymsg=self signed certificate in certificate chain
 
 to=<aaaaaaaaaaaaaaaaaaaaaaaaaaaaaapapapaa@gmail.com>, ctladdr=<aszypula@domain.com> (0/0), delay=00:00:04, xdelay=00:00:04, mailer=esmtp, pri=32815, relay=gmail-smtp-in.l.google.com. [173.194.67.27], dsn=5.1.1, stat=User unknown
 
 to=postmaster, delay=00:00:04, mailer=local, pri=32815, dsn=5.1.1, stat=User unknown
 
 q4QMDsD6003982-q4QMDxD6003984: postmaster notify: User unknown
 
 to=postmaster, delay=00:00:00, mailer=local, pri=3839, dsn=5.1.1, stat=User unknown
 
 q4QMDsD6003982-q4QMDxD7003984: return to sender: User unknown
 
 Saved message in /var/spool/dead/dead.letter
 
Why Fortimail in in certain situations can’t see LDAP alias/users? P.S. I try to forward dead mails according to this instructions:
 • To forward dead mail to a valid recipient’s mailbox, if the FortiMail unit is operating in server mode, create a local email account named " postmaster"  to receive these email messages, or create an alias named " postmaster"  to an existing email account, instead of using the dead mail folder. For details, see “Configuring local user accounts (server mode only)” and “Configuring aliases”.
 
but without effect. Please help! :) Best regards, Adam Szypuła
1 REPLY 1
aszypula
New Contributor

When I enable DSN and disable address mapping (I create mapping between aszypula@domain.com (internal) <> adam.szypula@domain.com (external)), I receive error delivery messages - works OK. When I enable address mapping and create alias adam.szypula@domain.com > aszypula@domain.com (local on fortimail) - it works OK. When I create LDAP alias it doesn' t work. Is any option to do it with address mapping and without alias (local)? Why LDAP alias doesn' t work? P.S. In my opinion Fortimail (DSN) is trying to find sender email addres only in local users, local user aliases and LDAP users. Why fortimail doesn' t try to resolve user account from LDAP alias address?
Labels
Top Kudoed Authors