NGFW Mode: Profile-based vs Policy-based
I'm spinning up a new pair of FortiGate 901G's to replace some Cisco FTD's (yuck!). I'm very used to and appreciative of Palo's way of doing security policy, centralized NAT, and a separate decryption policy. I like being able to make security policy directly based on app or URL category, rather than making profiles for everything. I don't see how profile mode is as flexible as policy mode. If I want to make a policy for a single app to be let through, I can't do that with profile mode, as an app control profile allows and denies all apps. For example, say I want to allow the "Quickbooks" app. I can't make a policy that has an app control profile of just allowing Quickbooks.. The app control policy would either end up blocking or allowing all apps. This is where i see the biggest downside to profile mode.
I've spoken to a few people I respect in the Fortinet world, and they recommended staying with Profile mode for varying reasons...
- I heard there is less support for Policy-based mode
- Some apps not recognized or usable in policy mode (maybe 20% or less?)
- cannot use Proxy inspection mode, but only flow-based (does this matter?)
So what's the consensus? I'm very tempted to roll with policy-based, but I don't want to get burned during my migration.
