Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sushil
New Contributor

Mail delivery delayed due to external smart host using fortinet

Hi, In my mail server I am using an external smart host to send email. Smart Host (hosted at ISP) ----Fortinet-----SMTP Server(Internal) Without fortinet all works fine.The mail server is having an internal ip.In normal scenrio mail from internal user is routed thorugh internal mail server and then smart host having public ip.Now once fortinet is placed natting is done on it smtp traffic is not flowing.Simple natting(rather pattin) is done to mail server like other internal hosts to outside world.Do I need to make any other changes in firewall polciy specific for internal mail server to this smart host????? Reg, Sushil
4 REPLIES 4
rwpatterson
Valued Contributor III

You do not need to inbound NAT for the firewall to work. NAT is so that the RFC3330 IP addresses (10.x.x.x, 172.16.x.x & 192.168.0.x) can be routed across the Internet. Doesn' t hold for inward traffic...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
sushil

Thanks Rwpatterson for your reply. The delivery of the mail system is delaying once FG is placed. I am thinking of creating a policy from internal mail server to smart host ip and allowing the smtp and dns traffic and placing this traffic above all policies.Also keep smtp scanning on AV and AS turned off.Will smtp traffic flow at all by this if keep policy above all as natting to this host is done in next policy. Getting little confused over this. It has delayed some 70% of mails and finally sending NDR. Reg, Sushil
rwpatterson
Valued Contributor III

I would create a stand alone SMTP policy and place it before all others. If you decide to use a protection profile, this could have components added/removed without affecting the other users. Perhaps you can narrow down what (if any) single component is disrupting mail flow.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jmmidire

You may want to try pointing the SMTP server to the Fortinet internal IP. I'm assuming you are using exchange as your mail server!

Labels
Top Kudoed Authors