Configuring DNS records
Transparent mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
120
Revision 2
Unless you have enabled both
Hide the transparent box
in each protected domain and
Hide this box from the mail server
in each session profile, the FortiMail unit is
not
fully
transparent in SMTP sessions: the domain name and IP address of the FortiMail unit may
be visible to SMTP servers, and they might perform reverse lookups. For this reason,
public DNS records for the FortiMail unit usually should include reverse DNS (RDNS)
records.
Case 1: Web Release Host Name/IP is empty/default
By default (that is, if
Web Release Host Name/IP
is unconfigured), the web release/delete
links that appear in spam reports will use the fully qualified domain name (FQDN) of the
FortiMail unit.
For example, if the FortiMail unit’s host name is
fortimail
, and its local domain name is
example.net
, resulting in the FQDN
fortimail.example.net
, a spam report’s
default web release link might look like (FQDN highlighted in bold):
https://
fortimail.example.net
/releasecontrol?release=0%3Auser2%40e
xample.com%3AMTIyMDUzOTQzOC43NDJfNjc0MzE1LkZvcnRpTWFpbC00MDAsI0YjU
yM2NTkjRSxVMzoyLA%3D%3D%3Abf3db63dab53a291ab53a291ab53a291
In the DNS configuration to support this and the other DNS-dependent features, you
would configure the following three records:
example.net IN MX 10 fortimail.example.net
fortimail IN A 10.10.10.1
1 IN PTR fortimail.example.net.
where:
•
example.net
is the local domain name to which the FortiMail unit belongs; in the MX
record, it is the local domain for which the FortiMail is the mail gateway
•
fortimail.example.net
is the FQDN of the FortiMail unit
•
fortimail
is the host name of the FortiMail unit; in the A record of the zone file for
example.net, it resolves to the IP address of the FortiMail unit for the purpose of
administrators’ access to the web-based manager, email users’ access to their per-
recipient quarantines, to resolve the FQDN referenced in the MX record when email
users send Bayesian and quarantine control email to the FortiMail unit, and to resolve
to the IP address of the FortiMail unit for the purpose of the web release/delete
hyperlinks in the spam report
•
10.10.10.1
is the public IP address of the FortiMail unit
Case 2: Web Release Host Name/IP is configured
You could configure
Web Release Host Name/IP
to use an alternative fully qualified
domain name (FQDN) such as
webrelease.example.info
instead of the configured
FQDN, resulting in the following web release link (web release FQDN highlighted in bold):
https://
webrelease.example.info
/releasecontrol?release=0%3Auser2%4
0example.com%3AMTIyMDUzOTQzOC43NDJfNjc0MzE1LkZvcnRpTWFpbC00MDAsI0Y
jUyM2NTkjRSxVMzoyLA%3D%3D%3Abf3db63dab53a291ab53a291ab53a291
Then, in the DNS configuration to support this and the other DNS-dependent features, you
would configure the following MX record, A records, and PTR record (unlike
Release Host Name/IP is empty/default” on page 120
, in this case, two A records are
required; the difference is highlighted in bold):
example.net IN MX 10 fortimail.example.net
fortimail IN A 10.10.10.1
webrelease IN A 10.10.10.1
1 IN PTR fortimail.example.net.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...