
Explain how email moves from a user client to internal and external mail servers, using SMTP, DNS, MX records, POP3 and IMAP, with DKIM, SPF, and DMARC.
Explore FortiMail deployment modes—gateway, transparent, and server—and learn from GLAB theory how it scans email for viruses and spam, applies access rules, verifies recipients, and integrates with LDAP/AD and DNS.
Build and test a private email ecosystem using a mail server, Thunderbird clients, and dns mx records, then verify mail delivery across internal and external domains via simulated firewall path.
Set up FortiMail in gateway mode to relay mail between internal and external servers, configure initial CLI and GUI settings, DNS, SMTP relay, inbound and outbound scanning, and access controls.
Master Fortinet Fortimail 7.2 networking interfaces, including VLAN subinterfaces, redundant and loopback interfaces, plus link monitor; covering static and default routing, DNS and dynamic DNS, port forwarding, and WCCP integration.
Practice configuring Fortinet Fortimail 7.2 link monitor to switch from one-arm to two-arm deployments, monitoring port three for internal traffic and triggering port one to block external mail.
Create admin accounts and profiles with defined access levels and authentication options (local or third-party). Enforce restrictions with trusted hosts, domains, and policy controls across cli, gui, and rest api.
Configure Fortinet Fortimail 7.2 mail settings, including smtp ports and tls, imap/pop3 ports, and dsn handling. Enable outgoing relay, disclaimer rules (body and header), and exclusion lists.
Configure global settings for Fortimail, including time zone and NTP synchronization, idle timeouts, login banners, and password policies, then manage administration ports, SNMP, REST API, and HTTPS redirection.
Explore Fortinet Fortimail 7.2 high availability, comparing active passive and config only modes, and learn how heartbeat and synchronization maintain failover, data integrity, and load balancing across two units.
Configure config-only high-availability for Fortinet Fortimail using F5 Big-IP LTM to load balance SMTP traffic across two mail nodes with a pool and virtual server.
Explore Fortiguard settings and Fortinet threat intelligence powering antivirus, anti-spam, url protection, and content disarm across Fortimail, with licensing, updates, and Microsoft 365 integration.
Configure a protected domain with domain and user options, including subdomain checks, smtp relay, ldap recipient verification, and alias and address map features for hiding and dkim, dmarc, spf support.
Learn how identity-based encryption for email works in FortiMail 7.2, encrypting messages using email addresses as public keys without certificates, and configuring IP encryption with profiles and policies.
Understand s/mime encryption using public and private keys, certificate bindings, and encryption profiles to encrypt and decrypt emails.
Explains how Fortimail's recipient verification address uses an LDAP or Active Directory profile to verify recipient existence, configure domain settings, and test mail flow with successful and rejected deliveries.
Master FortiMail access control rules for receiving and delivery of SMTP traffic, including open relay prevention, authentication, and encryption options. Configure sender, recipient, source patterns and actions.
Learn how IP policy and recipient policy operate in Fortinet Fortimail 7.2, configure source and destination, actions, and profiles, and apply precedence rules in gateway and server modes.
Configure session profiles to govern smtp session initiation and inbound and outbound mail, using sender reputation, fortiguard reputation, and spf, dkim, and dmarc checks for authentication.
Configure the inbound session profile to apply DKIM signing and SPF checks, then generate private and public keys with OpenSSL and publish the public key to DNS for outbound signing.
Explore anti-spam profile settings in Fortimail, configuring Fortiguard components such as IP reputation and URL category, SPF/DKIM/DMARC checks, impersonation and behavior analysis, and final actions like reject, quarantine, and rewrite.
Explore anti-spam profile actions in Fortinet Fortimail 7.2, comparing default versus per-rule actions like system quarantine and user quarantine, SPF check outcomes, tagging, and quarantine monitoring.
Configure anti-spam profiles with FortiGuard URL filtering to block or tag messages containing social media or education URLs, then test mail flow and review logs.
Configure the impersonation profile in anti-spam to detect spoofed emails, using manual pattern rules or auto analysis, and discard messages impersonating Bob at test local.
Create and apply a dictionary profile to an anti-spam profile to detect visa card numbers using a regular expression, then test outbound emails and discard matched traffic.
Configure antivirus profile settings in Fortinet Fortimail 7.2, including file signatures, malware outbreak protection, and sandbox analysis. Define actions like repackage or discard infected emails within policy.
Master Fortimail content profile settings to apply content based encryption, block prohibited content, and configure attachment scan rules with file filters by application or extension, archive handling and password decryption.
Demonstrates creating content profiles and file filter rules in Fortinet Fortimail 7.2, configuring attachment scan actions, and testing discard or reject outcomes for text and image files.
Learn how to apply scan options in content profile to detect password protected office or pdf documents, limit attachments and message size, and discard noncompliant emails.
Explore content disarm and reconstruction in Fortinet Fortimail 7.2, configuring HTML content handling, converting HTML to text, removing active content, and URL filters to secure email messages.
Explore encrypted file decryption methods in Fortinet Fortimail 7.2, using a user-defined password list and a built-in dictionary to decrypt office and PDF documents before antivirus scanning.
Explore archive handling in content profiles by decrypting encrypted archives with a built-in password list, and learn word-based decryption using email keywords and password strategies.
Learn to use content profile and dictionary profile to filter sensitive data, such as credit card numbers, for data loss prevention in outbound email, discarding content from body and attachments.
Create email groups, IP groups, and geo location groups to streamline FortiMail policies. Manage four levels of block and safe lists—system, session, domain, and personal—for targeted control.
Master advanced backups and restoration on Fortinet Fortimail 7.2, covering system, user, and IBE data, plus mail data and a full migration between appliances using remote backups.
Execute advanced Fortimail backups and restore operations to migrate configurations, user data, quarantine mail data, and block and save lists to a new appliance via NFS backups.
Explore how to implement personal quarantine in Fortinet Fortimail by integrating LDAP with Active Directory, configuring recipient and resource profiles, and enabling webmail access to release or manage quarantined messages.
This is course will be a practical training on fortinet fortimail through a giant lab that simulates a real world corporate network .
Fortimail is used mainly to secure the mail traffic from and to your mail server internally .
First section is simply a quick introduction to the mail traffic and it's relationship with the dns records that need to be published publically to the whole world .
Second section will be about establishing the lab that we will be use during the other full sections and apply fortimail features .
In the third section we will engage fortimail in the path between two mail servers to accept and recieve the smtp connections "gateway".
In the fourth section we will tackle everything related to the administration of the box from multiple sides like mail settings , networking , customizations , ..
In the fifth section we will quickly tackle the needs of user aliases and how to check and edit the domain settings .
Sixth section will be a quick lab on how to encrypt the traffic that will get out from fortimail by using IBE "Identity Based Encryption" .
In the seventh section we will configure the recipient address verification to make sure that each email address existed in RECPT part of the message sent from the external world existed in the internal mail server .