FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kcheng
Staff & Editor
Staff & Editor
Article Id 316787
Description This article describes the issue where Explicit Proxy cannot be enabled starting FortiOS 7.4.4.
Scope FortiGate v7.4.4 and above.
Affected FortiGate models: FortiGate/FortiWiFi-30G, 40F, 50G, 60E, 60F, 61F, 80E, and 90E series of devices and their variants, and FortiGate-Rugged 50G and 60F.
Solution

In older builds, the explicit proxy feature can be enabled on FortiGate 2GB models after enabling the following commands:

 

config system global
   set proxy-and-explicit-proxy enable
end


config system settings
   set gui-proxy-inspection enable
end

 

Starting from v7.4.4, proxy-related features have been removed from 2GB models:

2 GB RAM FortiGate models no longer support FortiOS proxy-related features

Proxy-related features not supported on FortiGate 2 GB RAM models NEW

 

Hence, the option to enable proxy-and-explicit-proxy has been removed:

 

proxy-explicit.png

 

Due to the respective, it would not be possible to enable the feature in the GUI despite the option showing up in Feature Visibility:

 

GUI_Proxy.png

 

If the explicit proxy is required, consider upgrading the FortiGate model with 4GB memory or above.

Note:

This solution is only applicable when the FortiGate NGFW is operating in Profile-Based mode. It does not apply to Policy-Based mode configurations.