Flow vs proxy based UTM best practices
I'm curious what people are doing / finding in terms of flow based vs. proxy based antivirus at this point.
I noticed in the 5.6.3 release notes that for new installs they're hiding the option for proxy based services from the GUI and you have to go to the CLI to even turn it on. But I'm wondering if this is a marketing thing about driving people who do performance tests to use it in flow mode... or if they truly think most customers should be using flow mode at this point.
The documentation hedges the bets a bit by implying that if you really really need good protection you should probably use proxy mode but otherwise flow mode is just super.
I tried out flow mode when it first came out and had really bad results... so I'm a bit hesitant at this point. I know it's a completely rewritten feature at this point... but overall I'm wondering what the tradeoff is for performance/security/lack of problems for proxy vs. flow.
Anyone have any experience they can share?
Thanks!
