proxy vs flow based AV check
Hello,
According to the Fortinet docs, flow based AV scanning should be (nearly) as secure as proxy based(from FortiOS 5.2.x on) which is more resource intensive. Now I have a customer who just received the trojan.agent.bpwv on his desktop, i.e. Fortigate didn't detect it. The Fortigate is configured with flow based scanning and the infected file came in through smtp.
I was wondering if this also might have been the case if we did configure proxy based scanning, or whether someone have had any comparable cases.
Thanks and regards,
Ralph Willemsen
Arnhem, Netherlands