Use the Mail Server page to send incident alerts. You can also create custom delivery rules.
- Go to System > Mail Server. The Mail Server page opens.
- Enable Send Incidents Alerts.
- Configure the mail server settings.
SMTP Server Address
SMTP server address.
SMTP server port number.
The mail server email account. This is the "from" address.
The mail server login account.
Enter and confirm the password.
- (Optional) Click Send Test Email to send a test email to one or more email addresses. If an error occurs, the error message appears at the top of the page and is recorded in the System Logs.
- Click Save.
- Click Reset to restore the default settings.
- Click Customer Alert Deliver Rule. The Custom Alert Rule dialog opens.
- Enable the rule. When enabled, FortiDeceptor sends an email alert to the Receiver Email List according to the rule
- Configure the rule settings.
Enter a name for the rule.
Select Low, Medium, High, or Critical.
Select Connection, Reconnaissance, Interaction, or Infection.
Incident Alert Section
Select All, Interaction Events Only, IPS events only, or Web filter events only.
This options is available when the Alert Type is Interaction or Infection .
Select Yes to be alerted when an attacker drops or downloads suspicious files into decoys.
Victim Decoy Service
Enter one or more decoy service port numbers.
Enter one or more receiver email addresses.
- Click Save.