Firewall Protection Profile Configuring a protection profile
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903 499
http://docs.fortinet.com/ • Feedback
extract any URL links. These URL links are sent to a FortiGuard Antispam server to
determine if any are listed. Spam messages often contain URL links to advertisements
(also called spamvertizing). If a URL match is found, FortiGuard Antispam terminates the
session. If FortiGuard Antispam does not find a match, the email server sends the email to
the recipient. The email checksum filter calculates the checksum of an email message and
sends this checksum to the FortiGuard servers to determine if the checksum is in the
blacklist. The FortiGate unit then passes or marks/blocks the email message according to
the server response.
To configure email filtering options, go to Firewall > Protection Profile. Select Create New
to add a protection profile, or the Edit icon beside an existing protection profile. Then
select the Expand Arrow beside Email Filtering, enter the information as described below,
and select OK.
You can configure email filtering for IMAP, POP3, and SMTP email. If your FortiGate unit
supports SSL content scanning and inspection you can also configure email filtering for
IMAPS, POP3S, and SMTPS email. For information about SSL content scanning and
inspection, see “SSL content scanning and inspection” on page 481.
For more information about the FortiGuard Antispam service, see
“FortiGuard Antispam
service” on page 323 and “Configuring the FortiGate unit for FDN and FortiGuard
subscription services” on page 323.
For more email filter configuration options, see “Email filtering” on page 567.
For information about character sets and email filter banned word, see “Character sets
and Web content filtering, Email filtering banned word, and DLP scanning” on page 495.
Figure 286: Protection Profile Email Filtering options
Note: Some popular email clients cannot filter messages based on the MIME header. For
these clients, select to tag email message subject lines instead.