Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smalle
New Contributor

The WAN IP "XXX.XXX.XXX.XXX" of this FortiGate has been blacklisted by one or more vendors

Morning, in my fortigate 800C, i see this error since 2 week. Help me please to resolve it.

3 REPLIES 3
emnoc
Esteemed Contributor III

Go to a RBL listing and confirm but basically you have a host or hosts sending spam from your  network or a open-mail-relay. I would allow mail from  only designated mail-servers and/or device. Read my HOWTO avoid being on a RBL

 

http://socpuppet.blogspot...ng-blocked-on-rbl.html

 

 

HINT:  I would started by doing  a google search for mxtoolbox and use the  open-relay checker against any exposed mail-servers.

 

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
Esteemed Contributor III

A quick remedy would be - IF you've got a second public IP - to create a secondary IP on your WAN interface to get your network connected. Of course, if there is a malware source on your LAN you'll burn this IP quickly.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
emnoc
Esteemed Contributor III

Or if he has a range of  subnet/address routed to him he could use a ippool and SNAT mail from a "non" BlackListed address ;)

 

 

 Either  way, he needs to fix the root cause to avoid being on a RBL to begin with ;)

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors