Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dommesb
New Contributor

Exchange in DMZ cannot connect to Internet Smarthost

Hello there,

I got a Problem.. and I am at a loss.

Im new to the Networking issue and try to get around.

 

So in my Company i got a Fortigate 240D. Config as Follows:

 

Wan1 = Internet - *.*.94.58 - Connection works

DMZ = 172.16.250.132

LAN = 172.21.10.*

Fortigate IP = 172.21.10.1

 

In the DMZ are my new virtual Servers hostet by an extern Company.

My hosted Exchange Server has the IP - 172.20.65.53

My old Exchange Server is in the LAN area. 172.21.24.8

 

Now im trying to get my new Exchange to connect to a smarthost in the Internet 212.88.138.119

Well thats not working.

Im trying to telnet from 172.20.65.53 to 212.88.138.119 25 - Connection fails

When i try to telnet from 172.21.24.8 to 212.88.138.119 25 - it works.

I also can telnet from 172.20.65.53 to 172.21.24.8 25

telnet also works from a client in the LAN

 

I enabled the explicit proxy so my Servers can access the internet through it. I also allowed smtp and pop3 in the security options. Working, as far as i have tested the proxy. FTP also working just fine.

 

I tried every ipv4 Policy i could imagine. dmz to lan allow all, dmz to wan allow all. nothings working so far.

 

What should be said is that i have to disable nat on the connections to and from the DMZ because Nat is done at the Provider.

 

I did read a lot about VIPS but I didnt seem to get it. I also dont know if thats my Way to go. I don't want to access the Server from the internet. I just want to send Mails to a smarthost and get Mails per POP3.

 

Somebody able to help?

Thanks

 

3 REPLIES 3
saifin
New Contributor II

Hi,

 

Please let me know, what is the default gateway configured in the server 172.20.65.53?

Please do collect packet capture from the source machine (172.20.65.53) and confirm it forwards the packet to the right gateway.

Also collect the capture from fortigate without interface condition,

# di snif pack any 'host 172.20.65.53 and host 212.88.138.119' 4 0

 

Please post the results here, will help you further.

 

Regards,

Saifin Thomas

Regards,

Saifin Thomas

Regards, Saifin Thomas
poundy

DMZ = 172.16.250.132 My hosted Exchange Server has the IP - 172.20.65.53

 

To me those addresses look wrong, unless you have a wacky subnet mask. I assume the IP you've listed for "DMZ" is the Fortigate interface address ? If so, you would need to have the Exchange server within the network boundary that the DMZ interface has. So something like 172.16.250.5 

 

But as Saifin said, check fundamentals like gateways and subnet masks before anything

ShawnZA
Contributor II

For the network your new exchange server is on....172.20.65.53 is that a /24?

What's the gateway? What's the rules on the firewall for that interface and subnet? Is that server sitting in your environment?

You say it's sitting in a new DMZ and hosted by an external company... so where exactly is this server?

Labels
Top Kudoed Authors