Skip to main content
Staff
February 27, 2023

Technical Tip: Using proxy features in lower-end FortiGates

  • February 27, 2023
  • 0 replies
  • 12208 views

Description

This article describes how to use the new proxy features implemented in version 7.2.4, as well as how to enable them in lower-end FortiGates.

Scope

FortiGate v7.2.4 and above affected FortiGate models: 30D, 30E, 30G, 40C, 40F, 50E, 50G, 60D, 60E, 60F, 70D, 80C, 80D, 80E, 90D, and 90E series of devices, including variants such as FortiWiFi, Rugged, 3G/4G, DSL, SFP, and POE, as long as the RAM is 2 GB or less.

Solution

To use some features (namely, the virtual server load balancer and security profile proxy features), it is necessary to configure a firewall policy or a security profile with proxy inspection mode.

 

There is a new feature ('gui-proxy-inspection') that is disabled by default on low-end platforms with 2GB or less RAM starting on v7.2.4. See the Release notes for more information.

 

When the settings 'gui-proxy-inspection' and 'proxy-and-explicit-proxy' are disabled, some features are greyed out or removed from the GUI:

 

2024-08-22 12_56_12-247372_proxyfeature.png

 

jfelix09_1-1677505968033.png

 

To enable Proxy Inspection on Firewall Policies, first log in to the FortiGate through the GUI and open a new CLI connection. Then, run the following commands:

 

config system settings
    set gui-proxy-inspection enable
end

 

Refresh the browser. Afterward, it will be possible to select the inspection mode on the desired firewall policy or enable certain required proxy features.

 

jfelix09_2-1677505968034.png

 

Note: This appears when creating new Security profiles for (webfilter, antivirus).

 

When the 'set gui-proxy-inspection' is disabled, the option to select (proxy/flow) will not be available, as per the image below:

 

image.png

 

To check the FortiGate device total RAM, run the commands below:

diagnose hardware sysinfo conserve


Notes: 

  • When using proxy features, the CPU and memory load may increase. This is because FortiGate buffers all traffic to make appropriate decisions when in proxy-based mode.

  • G-Series FortiGates with 2GB of memory, such as the FortiGate 30G, 50G, and their variants, do not support Proxy Features in any of the v7.2.x.

  • As part of performance and memory-usage improvements on FortiGates with 2 GB RAM or less, starting with v7.4.4, FortiOS no longer supports proxy-related features. This change impacts the FortiGate/FortiWiFi 40F, 60E, 60F, 80E, and 90E series of devices and their variants, and FortiGate-Rugged 60F (2 GB versions only).

  • Proxy-related features, including proxy-based Web Filter, Antivirus, DLP, File Filter, WAF, and Video Filter, can no longer be enabled on these devices, regardless of whether the applicable FortiGuard license is active.

  • Irrespective of the setting 'set gui-proxy-inspection', enabled or disabled on the affected devices, it is not possible to set the mode to proxy-based on the firewall policy for the affected low-end devices.

  • Starting with FortiOS v7.6.5, proxy-based email inspection with the following services is now supported for FortiGate models with 2GB RAM.

    • SMTP(s).

    • POP3(s).

    • IMAP(s).

    • NNTP.

Related documents:

Proxy-related features not supported on FortiGate 2 GB RAM models

Technical Tip: Cannot enable Explicit Proxy feature in FortiGate 2GB Model

Support proxy-based inspection for email protocols on models with 2 GB RAM

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!