Hot!Increase maximum message size

Page: 12 > Showing page 1 of 2
Author
rocklee44
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/05 00:57:23
  • Status: offline
2018/06/05 01:09:48 (permalink)
0

Increase maximum message size

Hi all,
This is my environment : Exchange server 2013 CU19 + Fortimail 400E Firmware version : v5.3,build653,180328 (5.3.12 GA)  operates as gateway mode

Outgoing messages : from Exchange server go straight to internet not via Fortimail
Incoming messages : are scanned by Fortimail before come to Exchange server
I want to increase maximum message size from 10MB (default) to 20MB, I followed document to edit Mail Settings --> Domains and Profile session but it doesn't work.



Incoming messages larger then 10MB are rejected "The response from the remote server was:
552 5.2.3 Message size (20611500) is over limit (10485760)
"
What should I do ? Please give me some advices , thank you very much.
I'm sorry, I tried to upload images but it doesn't show up, I will try again.
post edited by rocklee44 - 2018/06/06 18:57:04

Attached Image(s)

#1
Bromont_FTNT
Platinum Member
  • Total Posts : 558
  • Scores: 43
  • Reward points: 0
  • Joined: 2012/11/19 07:22:36
  • Status: offline
Re: Increase maximum message size 2018/06/05 06:03:46 (permalink)
0
Do you have an IP policy with a catch all (0.0.0.0/0) that contains the session profile with the 20MB limit?
#2
abelio
Expert Member
  • Total Posts : 3605
  • Scores: 51
  • Reward points: 0
  • Joined: 2005/03/31 13:28:59
  • Location: Buenos Aires, Argentina
  • Status: offline
Re: Increase maximum message size 2018/06/05 11:57:26 (permalink)
0
Hi Jack
 
rocklee44
 
Incoming messages larger then 10MB are rejected "The response from the remote server was:
552 5.2.3 Message size (20611500) is over limit (10485760)
"



For incoming messages, fortimail will check both domain settings and session profile matching your traffic.
Whether you don't provide session profile or IP policy matched as Bromont_FTNT said, the 10MB default value will be compared with the size limit you have defined in the domain configuration under "advanced settings". Lower value will be applied.
 
 
 
 
 
 

regards
--
Abel
#3
rocklee44
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/05 00:57:23
  • Status: offline
Re: Increase maximum message size 2018/06/05 19:00:33 (permalink)
0
Hello Bromont_FTNT and abelio, thanks for your replies, I know that fortimail will check both domain settings and session profile matching my traffic, I defined both of them and applied session profile to IP policy. I'm sorry something went wrong with image upload feature so my images cannot show up and I can only attach 1 image file 1 time. Please view my domain setting in attach file.
 

Attached Image(s)

#4
rocklee44
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/05 00:57:23
  • Status: offline
Re: Increase maximum message size 2018/06/05 19:06:27 (permalink)
0
This is my IP policy setting

Attached Image(s)

#5
rocklee44
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/05 00:57:23
  • Status: offline
Re: Increase maximum message size 2018/06/05 19:20:40 (permalink)
0
This is session profile which is applied to my ip policy
Disable / Enable IP Policy or restart Fortimail doesn't make it work too.
post edited by rocklee44 - 2018/06/06 00:46:13

Attached Image(s)

#6
Dirty_Wizard
Bronze Member
  • Total Posts : 45
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/05/23 07:32:52
  • Status: offline
Re: Increase maximum message size 2018/06/06 10:50:39 (permalink)
0
Is the client IP part of the 'Exchange IP Pool' group? Then it would hit 10MB limit since there's no Session Profile.
Can you attach the logs?
#7
rocklee44
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/05 00:57:23
  • Status: offline
Re: Increase maximum message size 2018/06/06 19:32:58 (permalink)
0
jwilkins
Is the client IP part of the 'Exchange IP Pool' group? Then it would hit 10MB limit since there's no Session Profile.
Can you attach the logs?


i don't understand what you mean , 'Exchange IP Pool' is a IP pool list my Exchange server ip address, there is Session Profile (Inbound from inter... - my IP policy setting picture above) applied to IP Policy, please also view my session profile SMTP Limits config as above picture.
When incoming message bigger than 10MB is rejected I got no logs from History , AntiSpam , Antivirus , except one entry in "Event" , please view event in attach picture.

Attached Image(s)

#8
abelio
Expert Member
  • Total Posts : 3605
  • Scores: 51
  • Reward points: 0
  • Joined: 2005/03/31 13:28:59
  • Location: Buenos Aires, Argentina
  • Status: offline
Re: Increase maximum message size 2018/06/07 08:13:20 (permalink)
5 (1)
Could you post please the cross log  for that specific event you've posted?
 
History log has IDs of matched ACL:IP policy: RCPT policy
That info could clarify this point
 
 

regards
--
Abel
#9
Bromont_FTNT
Platinum Member
  • Total Posts : 558
  • Scores: 43
  • Reward points: 0
  • Joined: 2012/11/19 07:22:36
  • Status: offline
Re: Increase maximum message size 2018/06/07 08:18:54 (permalink)
5 (1)
Destination should be 0.0.0.0/0 or the Fortimail IP
Currently IDs 3 and 4 aren't matched (for incoming) so it will use a default session profile with 10meg limit.
#10
ede_pfau
Expert Member
  • Total Posts : 5697
  • Scores: 385
  • Reward points: 0
  • Joined: 2004/03/09 01:20:18
  • Location: Heidelberg, Germany
  • Status: offline
Re: Increase maximum message size 2018/06/07 13:31:10 (permalink)
0
Destination should be 0.0.0.0/0 or the Fortimail IP
...as the MX record shows the FML's public IP address, not the Exchange server's.
 
BTW, this 'default 10 MB' limit, is it defined somewhere, or hardcoded?

Ede

" Kernel panic: Aiee, killing interrupt handler!"
#11
Bromont_FTNT
Platinum Member
  • Total Posts : 558
  • Scores: 43
  • Reward points: 0
  • Joined: 2012/11/19 07:22:36
  • Status: offline
Re: Increase maximum message size 2018/06/07 13:38:50 (permalink)
0
if it doesn't match an IP policy then it uses a "default" session profile which can't be changed. 
#12
Dirty_Wizard
Bronze Member
  • Total Posts : 45
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/05/23 07:32:52
  • Status: offline
Re: Increase maximum message size 2018/06/07 13:39:54 (permalink)
0
It's hardcoded as far as I know and documented here: http://help.fortinet.com/...elp/profile_09_09.html
#13
jack.chuong
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/07 20:49:53
  • Status: offline
Re: Increase maximum message size 2018/06/07 21:10:15 (permalink)
0
Hi ede_pfau, yes, FML's public IP address is listed in my domain mx records with highest priority.
 
Hi Bromont_FTNT,
IP Policy ID 3 will be used in future , when I want to route outgoing message through Fortimail, now outgoing messages are routed through internet and this IP Policy is defined for nothing (not use now), however is it defined right ? Please let me know if is wrong and how to fix it.
IP Policy ID 4 is used for incoming messages, if it is not matched for incoming , how to fix it ?
 
Hi abelio, like I said, When incoming message bigger than 10MB is rejected I got no logs from History , AntiSpam , Antivirus , except one entry in "Event", so this is when I "cross" log  for that specific event (please view image attact)
 As you can see there is no other "Log Type" except "Event".
Thank you for hint about ID Policy, when an incoming message is sent successfully to my system I notice that "cross" log provide full details including "History" , "AntiSpam" LogType, in "History" log I can see "Policy IDs" shows "0:0:1" , it proves that my IP Policy is not applied right ? How can I fix it ?
post edited by jack.chuong - 2018/06/07 21:15:49

Attached Image(s)

#14
Dirty_Wizard
Bronze Member
  • Total Posts : 45
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/05/23 07:32:52
  • Status: offline
Re: Increase maximum message size 2018/06/08 09:25:56 (permalink)
5 (1)
As Bromont said, the destination on policy ID 4 is incorrect. It should be the FortiMail IP or left as 0.0.0.0/0.
#15
jack.chuong
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/07 20:49:53
  • Status: offline
Re: Increase maximum message size 2018/06/08 18:54:59 (permalink)
0
jwilkins
As Bromont said, the destination on policy ID 4 is incorrect. It should be the FortiMail IP or left as 0.0.0.0/0.


Thank you, I will try and let you know result later.
Did I misunderstand the workflow ? If the destination on policy ID 4 is the FortiMail IP then incoming messages from Fortimail to Exchange server will be handled by "Domain setting" --> "Relay Type" --> "IP pool profile" ?
#16
Dirty_Wizard
Bronze Member
  • Total Posts : 45
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/05/23 07:32:52
  • Status: offline
Re: Increase maximum message size 2018/06/11 11:12:46 (permalink)
0
Right. The message from external hits the FortiMail and checks policy matching. Then is relayed on based on the domain settings.
#17
jack.chuong
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/07 20:49:53
  • Status: offline
Re: Increase maximum message size 2018/06/11 19:15:20 (permalink)
0
Thank you all, change the IP Policy 4 destination to FortiMail IP make it works, I can receive email larger than 10MB now. But I have another concern, it seems Fortimail add/increase incoming message size somehow , doesn't it ?
For ex:
In my first post , when it still limit 10MB as default, an incoming message with attached files about 15MB is rejected with error "The response from the remote server was: 552 5.2.3 Message size (20611500) is over limit (10485760)"
So if the limit is 20MB I cannot attach files larger then 15MB or it is rejected :
Attached files over 19MB : 552 5.2.3 Message size (27298309) is over limit (20971520)
Attached files about 17.5MB : 552 5.2.3 Message size (24372170) is over limit (20971520)
So If I want to receive message with attached files about ~20MB I have to set limit to 26 ~ 27 MB.
post edited by jack.chuong - 2018/06/11 19:17:11
#18
abelio
Expert Member
  • Total Posts : 3605
  • Scores: 51
  • Reward points: 0
  • Joined: 2005/03/31 13:28:59
  • Location: Buenos Aires, Argentina
  • Status: offline
Re: Increase maximum message size 2018/06/12 07:28:22 (permalink)
0
Hi Jack
jack.chuong
 But I have another concern, it seems Fortimail add/increase incoming message size somehow , doesn't it ?

 
Nothing related with Fortimail ;
 
https://en.wikipedia.org/wiki/Email_attachment
 
 

regards
--
Abel
#19
jack.chuong
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/07 20:49:53
  • Status: offline
Re: Increase maximum message size 2018/06/12 19:22:11 (permalink)
0
Hi abelio,
The Exchange message size limit is 20MB , I can send out a message (outgoing messages are routed straight to internet) with attached files ~19MB to my gmail.
When Fortimail limit is 20MB , I can send a message (from my gmail to my exchange mailbox) with attached files ~15MB , in my mailbox I also receive message with same size ~15MB , messages with size larger than 15MB will be rejected.
When Fortimail limit is 26MB , messages with size ~20MB will be ok.
So I think maybe there is something with the way Fortimail handle attached file messages, btw it works ok for me now so I won't bother you guys anymore , let's leave it for another day.
Thank you very much.
#20
Page: 12 > Showing page 1 of 2
Jump to:
© 2018 APG vNext Commercial Version 5.5