Skip to main content
lovepaloandfortigate
New Member
February 26, 2026
Solved

NGFW Mode: Profile-based vs Policy-based

  • February 26, 2026
  • 1 reply
  • 352 views

I'm spinning up a new pair of FortiGate 901G's to replace some Cisco FTD's (yuck!). I'm very used to and appreciative of Palo's way of doing security policy, centralized NAT, and a separate decryption policy. I like being able to make security policy directly based on app or URL category, rather than making profiles for everything. I don't see how profile mode is as flexible as policy mode. If I want to make a policy for a single app to be let through, I can't do that with profile mode, as an app control profile allows and denies all apps. For example, say I want to allow the "Quickbooks" app. I can't make a policy that has an app control profile of just allowing Quickbooks.. The app control policy would either end up blocking or allowing all apps. This is where i see the biggest downside to profile mode.

I've spoken to a few people I respect in the Fortinet world, and they recommended staying with Profile mode for varying reasons...
- I heard there is less support for Policy-based mode

- Some apps not recognized or usable in policy mode (maybe 20% or less?)

- cannot use Proxy inspection mode, but only flow-based (does this matter?)

 

So what's the consensus? I'm very tempted to roll with policy-based, but I don't want to get burned during my migration. 

Best answer by abarushka

Hello,

 

Profile based has certain advantages comparing to NGFW mode for example:

 

a) profile based inspection is FortiGate native and default inspection and is more feature reach

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Information-about-firewall-session-dirty/ta-p/195802

For example, "When using NGFW Policy-based mode, the only option available is check-all.".

 

b) performance reason (i.e. no offloading to ASIC in case of NFGW)

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Profile-based-policies-vs-Policy-based-policies/ta-p/195816

It is important to note that all the traffic will be inspected by IPSEngine even if no security-profiles or web-filter is applied. So, higher utilization is expected.


c) lack of proxy features (explicit proxy / UTM proxy specific features)

 

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/922096/inspectionmode-feature-comparison

 

 

1 reply

abarushka
Staff
abarushkaAnswer
Staff
February 27, 2026

Hello,

 

Profile based has certain advantages comparing to NGFW mode for example:

 

a) profile based inspection is FortiGate native and default inspection and is more feature reach

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Information-about-firewall-session-dirty/ta-p/195802

For example, "When using NGFW Policy-based mode, the only option available is check-all.".

 

b) performance reason (i.e. no offloading to ASIC in case of NFGW)

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Profile-based-policies-vs-Policy-based-policies/ta-p/195816

It is important to note that all the traffic will be inspected by IPSEngine even if no security-profiles or web-filter is applied. So, higher utilization is expected.


c) lack of proxy features (explicit proxy / UTM proxy specific features)

 

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/922096/inspectionmode-feature-comparison

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!