Example 1: FortiMail unit behind a firewall Server mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
142 Revision 2
http://docs.fortinet.com/ • Feedback
Figure 49: Public and private DNS servers (server mode)
If the FortiMail unit is operating in server mode, the private DNS server should contain
identical records to a public DNS server.
If you choose to add a private DNS server, to configure the FortiMail unit to use it, go to
System > Network > DNS in the advanced mode of the web-based manager.
Example 1: FortiMail unit behind a firewall
In this example, a FortiMail unit operating in server mode and email users’ computers are
both positioned within a private network, behind a firewall. Remote email users’ computers
and external email servers are located on the Internet, outside of the network protected by
the firewall. The FortiMail unit hosts and protects accounts for email addresses ending in
“@example.com”.
Figure 50: Server mode deployment behind a NAT device
External
Em ail Server
Local Em ail Users
Rem ote Em ail Users
Public DNS Server
Internet
dm z
192.168.1.1
wan1
10.10.10.1
port1
192.168.1.5
internal
172.16.1.1
(v irtual IP:
172.16.1.2)
Em ail Dom ain:
@example.com
exam ple.com IN MX 10 fortimail.exam ple.com
fortimail IN A 10.10.10.1
Server Mode
Private DNS Server
External
Em ail Server
Local Em ail Users
DNS Server
Internet
Sw itch
internal
172.16.1.1
wan1
10.10.10.1
Rem ote Em ail Users
port1
172.16.1.5
Em ail Dom ain:
@example.com
exam ple.com IN MX 10 fortimail.exam ple.com
fortimail IN A 10.10.10.1