Transparent mode deployment
Example 2: FortiMail unit in front of an email hub
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
Revision 2
127
•
4
Select
OK
.
To configure the transparent mode options of the session profile
1
Go to
Policy > Policies > IP Policies
in the advanced mode of the web-based manager.
2
In the
Session
column for an IP-based policy, select the name of the session profile to
edit the profile.
3
Configure the following:
4
Select
OK
.
5
Repeat the previous three steps for each IP-based policy.
Configuring the proxies and implicit relay
When operating in transparent mode, the FortiMail unit can use either transparent proxies
or an implicit relay to inspect SMTP connections. If connection pick-up is enabled for
connections on that network interface, the FortiMail unit can scan and process the
connection. If not enabled, the FortiMail unit can either block or permit the connection to
pass through unmodified.
Hide the transparent box
(transparent mode only)
Enable to preserve the IP address or domain name of the
SMTP client for incoming email messages in:
•
the SMTP greeting (
HELO
/
EHLO
) in the envelope and in the
Received:
message headers of email messages
•
the IP addresses in the IP header
This masks the existence of the FortiMail unit to the protected
SMTP server.
Disable to replace the SMTP client’s IP address or domain
name with that of the FortiMail unit.
Note:
If the protected SMTP server applies rate limiting
according to IP addresses, enabling this option can improve
performance. The rate limit will then be separate for each
client connecting to the protected SMTP server, rather than
shared among all connections handled by the FortiMail unit.
Note:
Unless you have enabled
If this policy matches then
don't check for a recipient match
in the IP-based policy, this
option has precedence over the
Hide this box from the mail
server
option in the session profile, and may prevent it from
applying to incoming email messages.
Use this domain’s SMTP
server to deliver the mail
(transparent mode only)
Enable to allow SMTP clients to send outgoing email directly
through the protected SMTP server.
Disable to, instead of allowing a direct connection, proxy the
connection using the incoming proxy, which queues email
messages that are not immediately deliverable.
Connection Settings
Hide this box from the
mail server
(transparent mode only)
Enable to preserve the IP address or domain name of the
SMTP client in:
•
the SMTP greeting (
HELO
/
EHLO
) and in the
Received:
message headers of email messages
•
the IP addresses in the IP header
This masks the existence of the FortiMail unit.
Disable to replace the IP addresses or domain names with
that of the FortiMail unit.
Note:
Unless you have enabled
If this policy matches then
don't check for a recipient match
in the IP-based policy, the
Hide the transparent box
option in the protected domain has
precedence over this option, and may prevent it from applying
to incoming email messages.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...