Skip to main content
JeffreyMik
New Member
April 9, 2024
Question

Flow-based and proxy-based inspection explanation needed

  • April 9, 2024
  • 5 replies
  • 8957 views

Hello,

 

I have a number of questions regarding flow and proxy-based inspection on the Fortigate firewall. As far as I understand, the inspection modes can be set at both the policy and security profile levels (for some profiles).

 

1. Why should I opt for flow-based inspection within a policy, instead of proxy-based?

 

2. Why is it possible to set flow-based inspection at the policy level and then set a proxy-based inspection at the security profile level and add t his profile to the flow-based policy?

 

3. Which SSL inspection (Certificate inspection / DPI) should be used for the specific security profiles?

 

I've done some research on the various inspection possibilities, but it's still not clear to me how it works. Does anyone have tips and/or answers to my questions?

 


Thank you in advance,

 

Jeffrey

5 replies

hbac
Staff
Staff
April 9, 2024

Hi @JeffreyMik,

 

Please refer to the admin guide: https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/721410/inspection-modes

 

Regards, 

ozkanaltas
Valued Contributor III
April 9, 2024

Hello @JeffreyMik ,

 

1- Flow mode uses less resources rather than proxy mode. Because of that, my choice is flow mode. 

2-You can't use different types of policy and security profiles together. If you select proxy mode in the security profile you should enable proxy mode in policy.

3-You can use SSL deep-inspection for web filters, AV,ips, etc.. In summary, you need to use deep-inspection, if traffic uses SSL encryption. 

 

These images explain clearly the differenties between proxy mode and flow mode. 

 

Flow ModeFlow ModeProxy ModeProxy Mode

 

 

If you wan to get more information about flow and proxy-based inspection mode, you can review these articles and also you can find a lot of discussion in the community. 

 

 

https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/922096/inspection-mode-feature-comparison

 

https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/659145/flow-mode-inspection-default-mode

 

 

https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/969330/proxy-mode-inspection

 

 

JeffreyMik
New Member
April 10, 2024

So for my understanding. When I configure my policy using flow-based inspection and I configure an antivirus profile with flow-based, I need to use deep-packet inspection in order to inspect SSL-encrypted traffic?

And when I use flow-based, packets are checked packet-by-packet and when a vulnerability is found by the Fortigate, the connection gets closed between the server and the client?

Is it true that no replacement message can't be shown to the client when using flow-based inspection, because the Fortigate isn't in between the host and the server as shown in your proxy-based picture? 

akumar02
Staff & Editor
Staff & Editor
April 9, 2024

Hello Jeffrey,

 

Flow-based inspection takes a snapshot of content packets and uses pattern matching to identify security threats in the content.

Proxy-based inspection reconstructs content that passes through the FortiGate and inspects the content for security threats.

 

Ref: https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/721410/about-inspection-modes#:~:text=Flow%2Dbased%20inspection%20takes%20a,the%20content%20for%20security%20threats.

 

This Forum post is also useful:

https://community.fortinet.com/t5/Support-Forum/Proxy-based-vs-Flow-based-Inspection-Mode-for-Web-Filter/m-p/19204

 

The default mode is Flow mode in Fortigate policies and Proxy mode can be used if you are using any proxy options. (e.g. Proxy policy)

Differences between SSL Certificate Inspection and Full SSL Inspection

 

https://community.fortinet.com/t5/FortiGate/Technical-Note-Differences-between-SSL-Certificate-Inspection/ta-p/192301

 

........

Arun

Maerre
Explorer III
April 10, 2024
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!