Example 2: FortiMail unit in front of a firewall
Server mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
148
Revision 2
Figure 51: Server mode deployment in front of a NAT device
The FortiMail unit has also been configured with an access control rule that allows local
and remote email users to send email to unprotected domains if they first authenticate:
To deploy the FortiMail unit in front of a NAT device such as a firewall or router, you must
complete the following:
•
•
Configuring the email user accounts
•
•
Configuring the firewall
With the FortiMail unit in front of a FortiGate unit which is between the FortiMail unit and
local email users, you must configure a policy to allow from local email users to the
FortiMail unit.
To create the required policies, complete the following:
•
Configuring the firewall addresses
•
Sender Pattern
*@example.com
Recipient Pattern
*
Sender IP/Netmask
0.0.0.0/0
Reverse DNS
Pattern
*
Authentication
Status
authenticated
TLS
< none >
Action
RELAY
External
Em ail Server
Local Em ail U sers
Rem ote Em ail U sers
Router
D N S Server
Internet
Sw itch
internal
172.16.1.1
w an1
10.10.10.1
port1
10.10.10.5
Em ail D om ain:
@ exam ple.com
exam ple.com IN M X 10 fortim ail.exam ple.com
fortim ail IN A 10.10.10.5
Note:
This example assumes you have already completed the Quick Start Wizard and
configured records on the DNS server for each protected domain. For details, see
and
“Configuring DNS records” on page 139
.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...