Example 3: FortiMail unit in DMZ
Gateway mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
112
Revision 2
Configuring the firewall
With the FortiMail unit in front of a FortiGate unit, and local email users and protected
email server located behind the FortiGate unit on its internal network, you must configure
firewall policies to allow traffic:
• between the internal network and the FortiMail unit
• between the protected email server and the Internet
• between the FortiMail unit and the Internet
To create the required policies, complete the following:
•
Configuring the firewall addresses
•
Configuring the service groups
•
•
Configuring the firewall policies
Configuring the firewall addresses
In order to create the firewall policies that governs traffic from the IP addresses of local
email users and the protected email server, and the IP address of the FortiMail unit, you
must first define the IP addresses of those hosts by creating firewall address entries.
To add a firewall address for local email users
1
Go to
Firewall > Address > Address
.
2
Select
Create New
.
3
Complete the following:
4
Select
OK
.
To add a firewall address for the FortiMail unit
1
Go to
Firewall > Address > Address
.
2
Select
Create New
.
3
Complete the following:
Note:
This example assumes you have already completed the Quick Start Wizard and
configured records on the DNS server for each protected domain. For details, see
and
“Configuring DNS records” on page 95
Note:
The following procedures use a FortiGate unit running FortiOS v3.0 MR7. If you are
using a different firewall appliance, consult the appliance’s documentation for completing
similar configurations.
Name
Enter a name to identify the firewall address entry,
such as
local_email_users_address
.
Type
Select
Subnet/IP Range
.
Subnet /IP Range
Enter
172.16.1.0/24
.
Interface
Select
internal
.
Name
Enter a name to identify the firewall address entry,
such as
FortiMail_address
.
Type
Select
Subnet/IP Range
.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...