Title: FortiMail
1FortiMail
- Jan Lundberg, Technical Manager Northern
Europejan.lundberg_at_fortinet.com - August 2006
2Email Security Challenges
- Action is needed to secure mail inbound and
outbound
Fortinet Confidential
3FortiGuard Antispam Service
- Fully managed service to help reduce obvious spam
content - Fortinet spam probes gather spam information
globally - AntiSpam databases are updated daily
- Enabled on either FortiGate or FortiMail platforms
Fortinet Confidential
4FortiGuard-Antispam
- FortiGuard-Antispam uses a number of filtering
techniques to detect and filter spam - FortiIP Sender IP reputation database
- IP address scoring
- FortiSig1 Spamvertised URLs
- Block messages that have spam hosts mentioned in
message bodies - Detect spam based on the URIs (usually web sites)
contained in the message body as opposed to the
spam origin (used by RBL) - FortiSig2 Spamvertised email addresses
- Lots of spam have an email address in the message
body that prompts one to contact the spammers.
Those email addresses are added to FortiSig - FortiSig3 Spam object checksums
- Objects in spam are identified and a fuzzy
checksum is calculated from each object which it
then added top the FortiSig database - Objects can be part of the message body or an
attachment - FortiRule
- FortiGuard also updates FortiMail local set of
heuristics rules
5FortiMail Advanced Spam Detection
- Access Policy Filtering
- Content Filtering
- Session Filtering (IP-based)
- Domain and User Black/White List Filtering
- Real-Time Blackhole List (RBL) Filtering
- Spam URI RBL (SURBL)
- Per User / Domain Bayesian Filtering
- Heuristics Rules (Dynamic updated Fortiguard)
- Greylist Filtering
- Image Analysis Filtering
- Local Reputation Filtering
Fortinet Confidential
6Per Detection Action
24
7PDF Content Scanning
26
8IP-Based Profiles
30
9Session profile
30
10FortiMail Inbound Multi-Layered Security
Inbound Risks
SMTP
Fortinet Confidential
11FortiMail Outbound Multi-Layered Security
SMTP
Outbound Risks
Fortinet Confidential
12FortiMail Simplifies Enterprise Email Security
- Static and legacy point product email messaging
security
- Flexible and turnkey FortiMail email messaging
security
Fortinet Confidential
13FortiMail Transparent Outbound Email Security
- Transparent carrier deployment protecting against
spam zombies
Fortinet Confidential
14FortiMail Operating Modes
- Transparent Mode (bridge mode)
- Requires no IP address changes
- Seamless integration into existing network
environments - FortiMail is placed in front of the existing
email server - Gateway Mode (relay mode)
- Proxy MTA services for existing email gateways
- DNS MX record change redirects email to FortiMail
- Server Mode
- Full email server functionality
- Full antivirus and antispam functionality
- Ideal for small to medium sized companies and
remote branch office locations (Models
FE-100/400) - Ideal for medium to large companies (Models
FE-2000)
Transparent
Gateway
Server
Fortinet Confidential
15FortiMail Transparent mode
- Seamless integration into existing network
environments - FortiMail is physically deployed in front of the
email server - Provides antivirus, antispam, archiving,
monitoring and reporting services - Requires no reconfiguration of the network
- FortiMail appears to other devices as a bridge
- All of its interfaces are on the same IP subnet
- FortiMail is acting as a transparent proxy
- No change to DNS MX records
SMTP Server
Corporate Mail server
Clients
Fortinet Confidential
16FortiMail Gateway Mode
- FortiMail is deployed as a mail relay
- Provides antivirus, antispam, archiving,
monitoring and reporting services
SMTP Server
Corporate Mail server
- With minor changes to the existing network
topology - DNS server is configured to ensure that incoming
SMTP traffic is sent to FortiMail before reaching
the email server - Optionally, email server can be configured to use
FortiMail as the relay server for outgoing SMTP
traffic
Clients
Fortinet Confidential
17FortiMail Server Mode
- Transparent Gateway mode features
- Mail server functionality
- Supports up to 500 email accounts (FE-100)
- Supports up to 1000 email accounts (FE-400)
- Supports up to 3000 email accounts (FE-2000)
- Webmail, SMTP, POP3 and IMAP client support
- Secure (SSL) WebMail client access
- Disk quota policy for user accounts
- Bulk Folder for spam mail
Mail Relay
SMTP Server
Clients
Supported accounts are guidelines only. Sizing
dependent on customer requirements, such as disk
quotas, etc.
Fortinet Confidential
18FortiMail Secure Email Messaging Platforms
- Large Enterprise/ Service Provider Deployments
- Over 295,200 emails/hour (Full-Inspection)
- RAID Support (4,8TB)
- Redundant/Hot-Swappable Power Supplies Fans
FortiMail-4000A
Fortinet Confidential
19