Skip to main content
Abin_FTNT
Staff
Staff
March 23, 2017

Technical Tip: No replacement message for application control when web filter is applied in proxy mode on same firewall policy

  • March 23, 2017
  • 0 replies
  • 4266 views

Description

 

This article describes that when the same firewall policy is applied with application control along with web-filter in a proxy mode no replacement message will be generated for application control.

Application control works only on flow-based and web filters can be proxy or flow-based.  Whenthe  web filter is proxy-based, the proxy will do SSL inspection, and decoded data will be sent to IPS for application control.
 
Scope
 
FortiGate.


Solution

 

Configure web filter in flow-based instead of proxy-based.  When the web filter is flow-based, together with AppCtrl, traffic will be processed inside the IPS engine, including SSL inspection.
 
config webfilter profile
 edit <profile name>
    set inspection-mode flow-based
   end
end
 

Note:

The command to change the inspection mode is different in higher versions.


Related article:

Technical Tip: Changing inspection mode

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!