Skip to main content
Jeff_Roback
New Member
April 5, 2018
Question

Flow vs proxy based UTM best practices

  • April 5, 2018
  • 12 replies
  • 55601 views

I'm curious what people are doing / finding in terms of flow based vs. proxy based antivirus at this point. 

 

I noticed in the 5.6.3 release notes that for new installs they're hiding the option for proxy based services from the GUI and you have to go to the CLI to even turn it on.  But I'm wondering if this is a marketing thing about driving people who do performance tests to use it in flow mode... or if they truly think most customers should be using flow mode at this point.  

 

The documentation hedges the bets a bit by implying that if you really really need good protection you should probably use proxy mode but otherwise flow mode is just super.

 

I tried out flow mode when it first came out and had really bad results... so I'm a bit hesitant at this point.   I know it's a completely rewritten feature at this point... but  overall I'm wondering what the tradeoff is for performance/security/lack of problems for proxy vs. flow.

 

Anyone have any experience they can share?

 

Thanks!

    12 replies

    Carl_Wallmark
    New Member
    April 5, 2018
    Im a proxy mode guy, as long as you dont have performance issues, go with proxy mode, it will give you a better security. There was a release some time ago that stated flow mode was as good as proxy but soon after the release that statement was gone. Proxy mode will always be better because the engine will have more data and time to unpack the files and also have a bigger picture of the files it is scanning. Proxy = better catch rate. Flow = better performance.
    tanr
    New Member
    April 5, 2018

    That's quite a change from 5.4, where they default to proxy and the docs say it is the best option.  Talking with Fortinet sales and support, though, they seemed to expect that most big 5.4.x installations would be using flow mode.

     

    I wonder what the docs say about proxy vs. flow in the 6.0 docs...

    terry_miesse
    New Member
    May 1, 2018

    I'm doing an upgrade to 5.6.3 and have been using proxy mode for a while now.  The one advantage I see (from reading) is that you can use session pickup to fail sessions over with flow mode but not with proxy.  The docs are a bit sketchy on this - anybody tried this? (ref. http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-high-availability/HA_failoverSessPickup.htm)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!