Transparent mode deployment
Example 3: FortiMail unit for an ISP or carrier
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
Revision 2
137
•
In this deployment example, two IP-based policies are configured. The first policy governs
connections from the internal subscriber network. The second policy matches all other
connections that did not match the first policy, and will therefore govern connections from
the external network.
To configure the IP-based policy for connections from internal SMTP clients
1
Go to
Policy > Policies > IP Policies
in the advanced mode of the web-based manager.
2
Select
New
.
3
In
Match client against
, type the IP address and netmask of your subscriber network.
4
In
Match server against
, type
0.0.0.0/0
to match all SMTP server IP addresses.
5
From
Session
, select
internal_session_profile
.
6
From
AntiSpam
, select the name of an antispam profile. When this profile detects
spam, it will affect the subscriber’s MSISDN reputation score.
7
From
AntiVirus
, select the name of an antivirus profile. When this profile detects a
virus, it will affect the subscriber’s MSISDN reputation score.
8
Select
OK
.
The internal network policy appears at the bottom of the list of IP-based policies.
Policies are evaluated in order until a policy is found that matches the connection.
Because the default IP-based policy (
0.0.0.0/0 --> 0.0.0.0/0
) matches all
connections, and because it is first in the list, in order for connections to be able to
match the new policy, you must move the new policy to an index number
above
the
default policy.
9
Select
Move
.
10
In
To
, type
1
.
11
Select
OK
.
The new policy for internal SMTP clients appears above the default policy, in the row
whose index number is 1.
To configure the IP-based policy for connections from external SMTP clients
1
Go to
Policy > Policies > IP Policies
in the advanced mode of the web-based manager.
2
Select
Edit
for the default policy whose
Match
column contains
0.0.0.0/0 --> 0.0.0.0/0
.
3
From
Session
, select
external_session_profile
.
4
From
AntiSpam
, select the name of an antispam profile. When this profile detects
spam, it will affect the SMTP client’s sender reputation score.
5
From
AntiVirus
, select the name of an antivirus profile. When this profile detects a
virus, it will affect the SMTP client’s sender reputation score.
6
Select
OK
.
Configuring the outgoing proxy
When operating in transparent mode, the FortiMail unit can use either transparent proxies
or an implicit relay to inspect SMTP connections. If connection pick-up is enabled for
connections on that network interface, the FortiMail unit can scan and process the
connection. If not enabled, the FortiMail unit can either block or permit the connection to
pass through unmodified.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...