Example 1: FortiMail unit behind a firewall
Gateway mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
98
Revision 2
Figure 41: Public and private DNS servers (gateway mode)
In some situations, a private DNS server may be required. A private DNS server is
required if you enable the
Use MX Record
option (see
).
Because gateway mode requires that public DNS servers have an MX record that routes
mail to the FortiMail unit, but
Use MX Record
requires an MX record that references the
protected SMTP server, if you enable that option, you must configure the records of the
private DNS server and public DNS server differently.
For example, if both a FortiMail unit (
fortimail.example.com
) operating in gateway
mode and the SMTP server reside on your private network behind a router or firewall as
illustrated in
, and the
Use MX Record
option is enabled,
illustrates differences between the public and private DNS servers for the
authoritative DNS records of example.com.
If you choose to add a private DNS server, to configure the FortiMail unit to use it, go to
System > Network > DNS
in the advanced mode of the web-based manager.
Example 1: FortiMail unit behind a firewall
In this example, a FortiMail unit operating in gateway mode, a protected email server, a
private DNS server, and email users’ computers are all positioned within a private
network, behind a firewall. Remote email users’ computers and external email servers are
located on the Internet, outside of the network protected by the firewall. The FortiMail unit
protects accounts for email addresses ending in “@example.com”, which are hosted on
the local email server.
Table 6: Public vs. private DNS records when “Use MX Record” is enabled
Private DNS server
Public DNS server
example.com IN MX 10
mail.example.com
example.com IN MX 10
fortimail.example.com
mail IN A 172.16.1.10
fortimail IN A 10.10.10.1
1 IN PTR fortimail.example.com
External
Em ail Server
Local Em ail U sers
Rem ote Em ail U sers
Public D N S Server
Internal Em ail Server
172.16.1.10
Internet
Sw itch
internal
172.16.1.1
w an1
10.10.10.1
port1
172.16.1.5
Protected D om ain:
@ exam ple.com
Em ail D om ain:
@ exam ple.com
exam ple.com IN M X 10 fortim ail.exam ple.com
fortim ail IN A 10.10.10.1
G atew ay M ode
Private D N S Server
exam ple.com IN M X 10 m ail.exam ple.com
m ail IN A 172.16.1.10
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...