Fortinet white logo
Fortinet white logo

Administration Guide

Configuring licensed features

Configuring licensed features

The following features are configurable if the FortiMail unit has a valid feature license.

Configuring email continuity

When FortiMail is running in either gateway or transparent mode, with this feature enabled, end users are allowed to access inbound emails in instances where the email server behind the FortiMail unit goes offline. This feature is only available with a valid license from FortiGuard.

To configure email continuity

  1. Go to System > FortiGuard > Licensed Feature.
  2. In theEmail Continuity section, set Status to Enable. Alternatively, you may select either Disable or Disable and Purge Email (to disable the feature and purge email from the email continuity service after the configured retention period expires).
  3. Adjust the Retention period according to your requirements. The higher the number, the higher the number of days emails are kept before they are removed. The default setting is 30. The valid range is 1-60.
    Caution

    The actual retention period is whichever is the smaller value of this setting and the email retention period set for incoming email when configuring a resource profile. See Configuring resource profiles.

    By default, this feature is disabled.

  4. Enable Authentication cache status to allow FortiMail to caches user's password, enabling users to authenticate in the event of an LDAP server outage.
  5. Define the Authentication cache period in days. The default setting is 20. The valid range is 1-60.

Configuring advanced management features

If you have an advanced management feature license, you can go to System > FortiGuard > Licensed Feature and in the Advanced Management section, enable the following settings.

GUI item

Description

Centralized monitor

For details, see Centrally monitoring the HA cluster.

User management

For details, see Configuring user import profiles

Mailbox accounting service

For details, see Configuring mailbox statistics and Viewing mail statistics.

Domain group support

For details, see To configure domain groups.

History log access for domain level administrator

For details, see Access level and Viewing log messages.

Domain mail statistics

For details, see Viewing mail statistics.

MTA advanced control

For details, see Configuring advanced MTA control settings.

Intra domain protection

Enable or disable applying both inbound and outbound policies when an email is sent between protected domains.

When this setting is disabled, if an email is sent between two protected domains, then FortiMail only applies the matching inbound policy. This means that, for example, an inbound policy with antispam would apply, but not an outbound policy with DLP. This behavior may be correct if all protected domains belong to the same company. However for an MSSP with multiple tenants, both policies should apply. In that case, enabled this setting so that FortiMail applies both inbound and outbound policies.

DMARC report analysis

For details, see Viewing DMARC report statistics.

Configuring licensed features

Configuring licensed features

The following features are configurable if the FortiMail unit has a valid feature license.

Configuring email continuity

When FortiMail is running in either gateway or transparent mode, with this feature enabled, end users are allowed to access inbound emails in instances where the email server behind the FortiMail unit goes offline. This feature is only available with a valid license from FortiGuard.

To configure email continuity

  1. Go to System > FortiGuard > Licensed Feature.
  2. In theEmail Continuity section, set Status to Enable. Alternatively, you may select either Disable or Disable and Purge Email (to disable the feature and purge email from the email continuity service after the configured retention period expires).
  3. Adjust the Retention period according to your requirements. The higher the number, the higher the number of days emails are kept before they are removed. The default setting is 30. The valid range is 1-60.
    Caution

    The actual retention period is whichever is the smaller value of this setting and the email retention period set for incoming email when configuring a resource profile. See Configuring resource profiles.

    By default, this feature is disabled.

  4. Enable Authentication cache status to allow FortiMail to caches user's password, enabling users to authenticate in the event of an LDAP server outage.
  5. Define the Authentication cache period in days. The default setting is 20. The valid range is 1-60.

Configuring advanced management features

If you have an advanced management feature license, you can go to System > FortiGuard > Licensed Feature and in the Advanced Management section, enable the following settings.

GUI item

Description

Centralized monitor

For details, see Centrally monitoring the HA cluster.

User management

For details, see Configuring user import profiles

Mailbox accounting service

For details, see Configuring mailbox statistics and Viewing mail statistics.

Domain group support

For details, see To configure domain groups.

History log access for domain level administrator

For details, see Access level and Viewing log messages.

Domain mail statistics

For details, see Viewing mail statistics.

MTA advanced control

For details, see Configuring advanced MTA control settings.

Intra domain protection

Enable or disable applying both inbound and outbound policies when an email is sent between protected domains.

When this setting is disabled, if an email is sent between two protected domains, then FortiMail only applies the matching inbound policy. This means that, for example, an inbound policy with antispam would apply, but not an outbound policy with DLP. This behavior may be correct if all protected domains belong to the same company. However for an MSSP with multiple tenants, both policies should apply. In that case, enabled this setting so that FortiMail applies both inbound and outbound policies.

DMARC report analysis

For details, see Viewing DMARC report statistics.