Skip to main content
ChrisTan
Staff
Staff
October 31, 2024

Technical Tip: Unable to select Profile Groups in SWG policy in FortiSASE

  • October 31, 2024
  • 0 replies
  • 286 views
Description This article describes how, in FortiSASE, the 'Application Control With Inline-CASB' will make the security profile invisible in the SWG policy.
Scope FortiSASE.
Solution

When creating an SWG policy in FortiSASE, the Security profile may be missing due to the 'Application Control With Inline-CASB' settings:

 

2024-10-21_13h35_38.png

 

The 'Application Control With Inline-CASB' profile contains a 'Proxy. HTTP' in the 'Proxy' category that cannot be blocked in the SWG policy.

 

2024-10-21_13h39_13.png

 

The only option to apply in SWG policy is to select 'Allow' or 'Monitor' for 'Proxy'.

 

Once the SWG policy is deployed with such a security profile, the 'Application Control With Inline-CASB' 'Proxy' can not be blocked.

 

2024-10-21_13h31_30.png

 

A separate SWG security profile is recommended to avoid conflicting with the SIA security profile.

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!