Fortigate Appriver Group

When it comes to security, we at Tech With a Hammer and found the best approach is to have multiple layers of security. One of the important pieces is incoming mail flow. There are an assortment of solutions that can vary in size and requirements, they can be a virtual machine in your network, a physical appliance installed in a rack, or an outside service that mail is routed through.

Of the solutions used we are impartial to Barracuda Spam Firewalls for the clients that would prefer to keep everything in-house, while Appriver is another service that is common to the industry. When it comes to locking down you on-premise Exchange servers another layer of security is to allow only Appriver IP addresses forward SMTP traffic to your server, we recommend disabling PAT for the incoming rule if possible as then the hosts will see traffic coming in from the external IP addresses instead of the firewall.

To make life easy, due to the number of Fortigate devices we have to configure, here is a quick snippet to cover all the network addresses and IPs that SMTP traffic can come through.

Leave a Reply

Your email address will not be published. Required fields are marked *