policy recipient
Use this command to create system-wide sender-or recipient-based policies based on the inbound or outbound directionality of an email message with respect to the protected domain.
Syntax
config policy recipient
edit <policy_index>
[set comment "<comment_str>"]
set direction {incoming | outgoing}
set sender-type {email-user-group | ldap-group | user-regex | user-wildcard}
set sender-option {envelope-from | header-from | envelope-or-header-from}
set sender-name "<local-part_str>"
set sender-domain "<domain_str>"
set sender-regex "<sender_pattern>"
set sender-email-address-group <group_name>
set profile-ldap-sender <ldap-profile_name>
set sender-exclusion-status {enable | disable}
set sender-exclusion-type {email-address-group | user-regex | user-wildcard}
set sender-exclusion-name "<local-part-str>"
set sender-exclusion-domain "<domain-part_str>"
set sender-exclusion-regex "<exclusion_pattern>"
set sender-exclusion-email-address-group <group_name>
set recipient-type {email-user-group | ldap-group | user-regex | user-wildcard}
set recipient-name "<local-part_str>"
set recipient-domain "<domain_str>"
set recipient-regex "<recipient_pattern>"
set recipient-email-address-group <group_name>
set profile-ldap-recipient <ldap-profile_name>
set recipient-exclusion-status {enable | disable}
set recipient-exclusion-type {email-address-group | user-regex | user-wildcard}
set recipient-exclusion-name "<local-part-str>"
set recipient-exclusion-domain "<domain-part_str>"
set recipient-exclusion-regex "<exclusion_pattern>"
set recipient-exclusion-email-address-group <group_name>
set profile-antispam <antispam-profile_name>
set profile-antivirus <antivirus-profile_name>
set profile-content <content-profile_name>
set profile-dlp <profile_name>
set profile-resource <profile_name>
set profile-auth-type {imap | ldap | local | none | pop3 | radius | smtp}
set profile-auth-imap <profile_name>
set profile-auth-ldap <profile_name>
set profile-auth-pop3 <profile_name>
set profile-auth-radius<profile_name>
set profile-auth-smtp <profile_name>
set auth-allow-smtp {enable | disable}
set pkiauth {enable | disable}
set certificate-required {yes | no}
set smtp-diff-identity {enable | disable}
set smtp-diff-identity-ldap {enable | disable}
set smtp-diff-identity-ldap-profile <profile_name>
end
|
Variable |
Description |
Default |
|
Enter the index number of the recipient-based policy. To view a list of existing entries, enter a question mark ( Note: The ID is automatically assigned when the policy is created, and may be different from its order in the list. See the order of execution for policies. |
|
|
|
Enable to allow the SMTP client to use the SMTP Disable to make SMTP authentication unavailable. This setting is available in gateway Note: This setting allows, but does not require, SMTP authentication. To enforce SMTP authentication, set |
|
|
|
Select Select This setting is available only if |
no |
|
|
Enter a comment or description. |
|
|
|
Select the direction of email that this policy matches, with respect to protected domains. |
incoming |
|
|
Enable if you want to allow webmail and personal quarantine users to log in by presenting a certificate rather than a user name and password. Also configure This setting is available only if |
disable |
|
|
Enter the name of a PKI user, such as This setting only applies if |
|
|
|
Select which antispam profile, if any, to apply to email matching the policy. Tip: You can use an LDAP query to enable or disable antispam scanning on a per-user basis ( |
|
|
|
Select which antivirus profile, if any, to apply to email matching the policy. |
|
|
|
Select an authentication profile. This setting is available only if |
|
|
|
Select an authentication profile. This setting is available only if |
|
|
|
Select an authentication profile. This setting is available only if |
|
|
|
Select an authentication profile. This setting is available only if |
|
|
|
Select an authentication profile. This setting is available only if |
|
|
|
profile-auth-type {imap | ldap | local | none | pop3 | radius | smtp} |
Select the type of the authentication profile that FortiMail will use to authenticate email users:
Depending on the type that you select, also configure |
none |
|
Select which content profile, if any, to apply to email matching the policy. |
|
|
|
Select which DLP profile, if any, to apply to email matching the policy. |
|
|
|
If |
|
|
|
If |
|
|
|
Select which content profile, if any, to apply to email matching the policy. This setting is available only if FortiMail is operating in server mode or gateway mode. |
|
|
|
Enter the local part (username) of recipient email addresses that match this policy. This setting is available only if |
|
|
|
Enter the group of recipient email addresses. This setting is available only if |
|
|
|
Enter the domain name of recipient email addresses that you want to exclude. This setting is available only if |
* |
|
|
Enter the group membership attribute value as it appears in the LDAP directory. This setting is available only if |
|
|
|
Enter the local part (username) of recipient email addresses that you want to exclude. This setting is available only if |
* |
|
|
Enter a regular expression that matches only recipient email addresses that you want to exclude, such as: .*@example\.com This setting is available only if |
|
|
|
Enable if you want to exclude some recipient email addresses from matching this policy. Also configure |
disable |
|
|
recipient-exclusion-type {email-address-group | user-regex | user-wildcard} |
Select how you want to define excluded recipient email addresses. Depending on which you select, also configure This setting is available only if |
user-wildcard |
|
Enter the local part (username) of recipient email addresses that match this policy. This setting is available only if |
|
|
|
Enter a regular expression that matches only the recipient email addresses that should match this policy. This setting is available if |
.* |
|
|
recipient-type {email-user-group | ldap-group | user-regex | user-wildcard} |
Select how to define recipient ( Depending on which you select, also configure |
user |
|
Enter the domain name of sender email addresses that match this policy. This setting is available only if |
|
|
|
Enter the group membership attribute value as it appears in the LDAP directory. This setting is available only if This setting is available only if |
|
|
|
Enter the domain name of sender email addresses that you want to exclude. This setting is available only if |
* |
|
|
Select a group of email addresses you want to exclude. This setting is available only if |
|
|
|
Enter the local part (username) of sender email addresses that you want to exclude. This setting is available only if |
* |
|
|
Enter a regular expression that matches only sender email addresses that you want to exclude, such as: .*@example\.com This setting is available only if |
|
|
|
Enable if you want to exclude some sender email addresses from matching this policy. Also configure Sender exclusion settings apply only if |
disable |
|
|
sender-exclusion-type {email-address-group | user-regex | user-wildcard} |
Select how you want to define excluded sender email addresses. Depending on which you select, also configure This setting is available only if |
user-wildcard |
|
Enter the local part (username) of sender email addresses that match this policy. This setting is available only if |
|
|
|
sender-option {envelope-from | header-from | envelope-or-header-from} |
Select which sender email addresses to compare for a policy match, either:
This setting is available only if |
envelope-from |
|
Enter a regular expression that matches only the sender email addresses that should match this policy. This setting is only available when |
.* |
|
|
sender-type {email-user-group | ldap-group | user-regex | user-wildcard} |
Select how to define sender ( Depending on which you select, also configure |
user-wildcard |
|
Select which LDAP profile to use for verifying an email user's other identities. This setting is applicable only if |
|
|
|
Enable to use a directory query to find and verify the sender's other email addresses. Also configure This setting is applicable only if Note: If verification succeeds, the sender email sender address in the SMTP envelope ( |
disable |
|
|
Disable to allow the SMTP client to send email using a different sender email address ( Enable to require that the sender email address in the SMTP envelope matches the authenticated user name, and reply with an SMTP rejection code if they don't match. This setting is applicable only if |
disable |
|
|
Enable to apply the policy. |
enable |