Using SMTP authentication in FortiMail
SMTP authentication can help mitigate brute force password attacks by tracking the IP addresses of the offending client attempting to connect to the box. SMTP authentication can detect, block, and punish hackers.
This recipe shows you how to enable SMTP authentication and check the SMTP authentication score and record. This recipe is undertaken solely in the CLI.
Use the following CLI commands to enable SMTP authentication. Also, if there is a gateway before the mail server, add the gateway to the exempt list, as shown below:
config system security authserver
set status enable
config exempt-list
edit 1
set sender-ip-mask 172.20.140.232/32
next
end
end
To display automatically added exempt IP addresses, enter the following CLI command:
diagnose system authserver display auto-exempt
To delete the IP address, enter the following CLI command:
diagnose system authserver delete auto-exempt <ip_address>