Skip to main content
ganapareddy
New Member
May 27, 2019
Question

How SSL Inspection Works when the session not terminate in the Firewall

  • May 27, 2019
  • 1 reply
  • 5793 views

Hi Experts

Please answer my below query.

I found that in both the flow based and the Proxy based inspection does not terminate the session in the firewall and it shows in flow mode it checks packet by packet and in proxy mode it check bunch of packets at a time. My question is how the ssl inspection works without terminating the session in the firewall like BIG-IP F5 full proxy. 

1 reply

hubertzw
New Member
June 3, 2019

Hi,

 

Inspection (once the traffic is decrypted) on the device in flow-based inspection mode is always performed by the IPS engine, which works only in the flow-based inspection mode. Inspection on the device in proxy-based inspection mode is performed by proxy (AV, Web Filtering, etc.) or by IPS engine: Application Control, IPS -> they are scanned by IPS engine, which works always in flow-based inspection mode even on FG, which works in the proxy-based inspection mode.

 

It means the device in flow-based inspection mode can perform inspection only in flow mode.

The device which works in proxy-based inspection mode performs inspection in proxy mode and only inspection performed by IPS engine is done in the flow-based mode (IPS, App Control).

 

 

 

 

SSL decryption - interesting question indeed. It looks like the decryption in flow and proxy inspection mode is performed (initiated) by different processes but at the end in both cases it is offloaded to CP.

 

Proxy based:

 “The packets are then sent to the FortiOS UTM/NGFW proxy for proxy-based inspection. The proxy first determines if the traffic is SSL traffic that should be decrypted for SSL inspection. SSL traffic to be inspected is decrypted by the proxy. SSL decryption is offloaded to and accelerated by CP8 or CP9 processors.

“Decrypted SSL traffic is sent to the IPS engine (where IPS and Application Control can be applied) before re-entering the proxy where actual proxy-based inspection is applied to the decrypted SSL traffic. Once decrypted SSL traffic has been inspected it is re-encrypted and forwarded to its destination. SSL encryption is offloaded to and accelerated by CP8 or CP9 processors. If a threat is found the proxy can block the threat and replace it with a replacement message.”

 

 

Flow based:

"Before flow-based inspection can be applied the IPS engine uses a series of decoders to determine the appropriate security modules to be applied depending on the protocol of the packet and on policy settings. In addition, if SSL inspection is configured, the IPS engine also decrypts SSL packets. SSL decryption is offloaded and accelerated by CP8 or CP9 processors."

 

 

Source:

https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-life-of-packet/lop-packet-flow-proxy.htm

https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-life-of-packet/lop-packet-flow-flow.htm

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!