Clarification Needed: Flow-Based vs Proxy-Based Inspection Performance Behavior in FortiOS 7.6
Hello,
I am reviewing the FortiOS 7.6 administration guide regarding inspection modes (pages 233–234), and I need clarification on the following point:
The documentation states that proxy-based mode provides more feature configuration options and is security-focused, while flow-based mode is designed to optimize performance.
However, it also mentions that flow-based mode can consume more CPU cycles than proxy-based mode in some cases, which appears contradictory:
Â
page 233 ..... While both modes offer significant security, proxy-based mode provides more feature configuration options,
while flow-based mode is designed to optimize performance .....If security is your priority, proxy-based inspection mode—with client comforting disabled—is more appropriate.If performance is your top priority, then flow-based inspection mode is more appropriate
.....
.....
page 234 ...... Because the file is transmitted at the same time, flow-based mode consumes more CPU cycles than proxy-
based mode. However, depending on the FortiGate model, some operations can be offloaded to secure
processing units (SPU) to improve performance.
Â
Could you please clarify the following:
- In general traffic processing, which mode provides higher overall throughput: flow-based or proxy-based?
- Under what specific conditions does flow-based consume more CPU than proxy-based?
- How does SPU/ASIC offloading affect performance comparison between both modes?
- For production environments prioritizing latency and throughput, which mode is recommended?
i would appreciate an architectural explanation rather than feature-level description to better understand the internal behavior.
Â
