Example 1: FortiMail unit in front of an email server
Transparent mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
122
Revision 2
If you choose to add a private DNS server, to configure the FortiMail unit to use it, go to
System > Network > DNS
in the advanced mode of the web-based manager.
Example 1: FortiMail unit in front of an email server
In this example, a FortiMail unit operating in transparent mode is positioned in front of one
email server.
Figure 46: Transparent mode deployment to protect an email server
The FortiMail unit has also been configured with an access control rule that allows local
and remote email users to send email to unprotected domains if they first authenticate:
To deploy the FortiMail unit in front of an email server, you must complete the following:
Table 7: Public vs. private DNS records when “Use MX Record” is enabled
Private DNS server
Public DNS server
example.com IN MX 10
mail.example.com
example.com IN MX 10
mail.example.com
mail IN A 172.16.1.10
mail IN A 10.10.10.1
10 IN PTR fortimail.example.com
1 IN PTR fortimail.example.com
Note:
This example assumes that the FortiMail unit is protecting a single email server. If
your FortiMail unit is protecting multiple email servers and they are not on the same subnet,
you must first remove some network interfaces from the bridge and configure static routes.
For an example of configuring out-of-bridge network interfaces, see
interfaces from the bridge” on page 133
.
Sender Pattern
*@example.com
Recipient Pattern
*
Sender IP/Netmask
0.0.0.0/0
Reverse DNS
Pattern
*
Authentication
Status
authenticated
TLS
< none >
Action
RELAY
External
Email Server
Local Email Users
Internet
Transparent Mode
Remote Email Users
Router
port2
port1
Internal Email Server
172.16.1.10
Protected Domain:
@example.com
Email Domain:
@example.com
Public DNS Server
example.com IN MX 10 mail.example.com
mail IN A 10.10.10.1
Private DNS Server
example.com IN MX 10 mail.example.com
mail IN A 172.16.1.10
10.10.10.1
Содержание FortiMail-100
Страница 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Страница 173: ...www fortinet com...
Страница 174: ...www fortinet com...