Example 2: FortiMail unit in front of a firewall
Gateway mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
104
Revision 2
4
Select
NAT
.
5
Select
OK
.
Configuring the MUAs
Configure the email clients of local and remote email users to use the FortiMail unit as
their outgoing mail (SMTP) server/MTA. For local email users, this is the private network
IP address of the FortiMail unit, 172.16.1.5; for remote email users, this is the virtual IP on
the FortiGate unit that maps to the FortiMail unit, 10.10.10.1 or fortimail.example.com.
If you do not configure the email clients to send email through the FortiMail unit, incoming
email delivered to your protected email server can be scanned, but email outgoing from
your email users cannot.
Also configure email clients to authenticate with the email user’s user name and password
for outgoing mail. The user name is the email user’s entire email address, including the
domain name portion, such as [email protected].
If you do not configure the email clients to authenticate, email destined for other email
users in the protected domain may be accepted, but email outgoing to unprotected
domains will be denied by the access control rule.
Testing the installation
Basic configuration is now complete, and the installation may be tested. For testing
instructions, see
“Testing the installation” on page 159
.
For information on configuring additional features, see the
FortiMail Administration Guide
.
Example 2: FortiMail unit in front of a firewall
In this example, a FortiMail unit operating in gateway mode within a private network, but is
separated from the protected email server and local email users’ computers by a firewall.
The protected email server is located on the demilitarized zone (DMZ) of the firewall. The
local email users are located on the internal network of the firewall. Remote email users’
computers and external email servers are located on the Internet, outside of the private
network. The FortiMail unit protects accounts for email addresses ending in
“@example.com”, which are hosted on the local email server.
Source Interface/zone
Select
wan1
.
Source Address Name
Select
all
.
Destination
Interface/zone
Select
internal
.
Destination Address
Name
Select
protected_email_server_VIP
.
Schedule
Select
ALWAYS
.
Service
Select
PO3_IMAP_services
.
Action
Select
ACCEPT
.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...