Example 3: FortiMail unit in DMZ Server mode deployment
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
156 Revision 2
http://docs.fortinet.com/ • Feedback
To add the Internet-to-FortiMail policy
1 Go to Firewall > Policy > Policy.
2 Select Create New.
3 Complete the following:
4 Select NAT.
5 Select OK.
To add the FortiMail-to-Internet policy
1 Go to Firewall > Policy > Policy.
2 Select Create New.
3 Complete the following:
4 Select NAT.
5 Select OK.
To add the internal-to-FortiMail policy
1 Go to Firewall > Policy > Policy.
2 Select Create New.
3 Complete the following:
Source Interface/zone Select wan1.
Source Address Name Select all.
Destination
Interface/zone
Select dmz.
Destination Address
Name
Select FortiMail_VIP_wan1.
Schedule Select ALWAYS.
Service Select FortiMail_incoming_services.
Action Select ACCEPT.
Source Interface/zone Select dmz.
Source Address Name Select FortiMail_address.
Destination
Interface/zone
Select wan1.
Destination Address
Name
Select all.
Schedule Select ALWAYS.
Service Select FortiMail_outgoing_services.
Action Select ACCEPT.
Source Interface/zone Select internal.
Source Address Name Select local_email_users_address.
Destination
Interface/zone
Select dmz.
Destination Address
Name
Select FortiMail_VIP_internal.
Schedule Select ALWAYS.