Example 1: FortiMail unit in front of an email server
Transparent mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
124
Revision 2
2
In the
Session
column for an IP-based policy, select the name of the session profile to
edit the profile.
3
Configure the following:
4
Select
OK
.
5
Repeat the previous three steps for each IP-based policy.
Configuring the proxies and implicit relay
When operating in transparent mode, the FortiMail unit can use either transparent proxies
or an implicit relay to inspect SMTP connections. If connection pick-up is enabled for
connections on that network interface, the FortiMail unit can scan and process the
connection. If not enabled, the FortiMail unit can either block or permit the connection to
pass through unmodified.
Exceptions to SMTP connections that can be proxied or relayed include SMTP
connections destined for the FortiMail unit itself. For those local connections, such as
email messages from email users requesting deletion or release of their quarantined
email, you must choose to either allow or block the connection.
Proxy/relay pick-up is configured separately for incoming and outgoing connections.
In this deployment example, incoming connections arriving on port2 must be scanned
before traveling to the main email server, and therefore are configured to be
are proxied
—
that is, picked up by the implicit relay.
Outgoing connections arriving on port1 will contain email that has already been scanned
once, during SMTP clients’ relay to the main email server. Scanning outgoing connections
again using either the outgoing proxy or the implicit relay would waste resources.
Therefore outgoing connections will be passed through.
To configure SMTP proxy and implicit relay pick-up
1
Go to
Mail Settings > Proxies
in the advanced mode of the web-based manager.
2
Configure the following:
Connection Settings
Hide this box from the
mail server
(transparent mode only)
Enable to preserve the IP address or domain name of the
SMTP client in:
•
the SMTP greeting (
HELO
/
EHLO
) and in the
Received:
message headers of email messages
•
the IP addresses in the IP header
This masks the existence of the FortiMail unit.
Disable to replace the IP addresses or domain names with
that of the FortiMail unit.
Note:
Unless you have enabled
If this policy matches then
don't check for a recipient match
in the IP-based policy, the
Hide the transparent box
option in the protected domain has
precedence over this option, and may prevent it from applying
to incoming email messages.
Note:
For information on determining directionality, see
Port 1
Incoming SMTP connections
are dropped
Outgoing SMTP connections
are passed through
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...