Question
Proxy-based vs. Flow-based Inspection Mode for Web Filter profiles?
Can someone explain the specific ways/differences in how the two Inspection Modes " Proxy-based" and " Flow-based" work in FortiOS v5.0.4 please? I had guessed that " Proxy-based" meant what we have clasically called " explicit proxy" , where the web browser would have to be configured to proxy to an IP address assigned to the FortiGate itself, and " Flow-based" meant what we have classically called " transparent proxy" . But I just did a test, switching the Web Filter Profile to Proxy based Inspection Mode, and without making any change in my web browser' s configuration, the FortiGuard Categories are properly applied. The FortiOS v5 handbook on page 774 gives a very brief treatment of Flow-based vs. Proxy-based, suggesting that flow-based is packet-by-packet, does no buffering, is faster; whereas proxy-based buffers up data objects which flow through the FortiGate, is slower, but could be more accurate. But I' ve been unable to find anything more detailed, and I' d prefer to know, so I can make a better decision as to what best serves my users' needs. Aside, this is brought up by the weird URL filtering effects I' ve been dicussing in another thread. So knowing more about how flow-based vs. proxy-based really works may help me understand better whether the noticeable number of apparently spurious alert messages my FortiGate is sending me about URLs which match filters, even though nothing like the " matched" URL exists in any filter on my FortiGate (in fact, I have one single filter, containing one single simple match " www.meneame.net" , so almost nothing should ever match it). thank you,
