Created on
‎12-27-2022
05:19 AM
Edited on
‎10-06-2025
09:50 PM
By
Anthony_E
Description |
This article describes how NGFW policy-based mode handles FortiGuard URL Category- and Application-based Filtering when operating in NGFW policy-based mode. |
Scope | FortiGate; NGFW policy-based mode |
Solution |
FortiGates support two modes for Next Generation Firewall (NGFW) functionality, which in-turn impact how security inspection and policy matching operate:
This functionality serves as a notable advantage for NGFW policy-based mode, where it becomes possible to have more granular policy matching, though at the slight cost of slower policy matching (the FortiGate must allow some traffic through so that it can scan, identify, and subsequently take action on that traffic). For example, an administrator could create Security Policies for traffic matching the Microsoft.Teams and Zoom Application signatures, rather than needing to whitelist based on IP ranges, FQDNs, and network ports. Note as well that this functionality does not require the administrator to apply a Web Filter profile to the Security Policy.
To change the FortiGate's NGFW mode use the following command:
config system settings set ngfw-mode [profile-based | policy-based] end
Note: changing the mode on an existing FortiGate/VDOM will result in all existing policies being deleted/removed, as the policy structure is significantly different between the two modes. It may also be necessary to log out and log back in to the FortiGate GUI to reflect the new mode's layout.
Once in NGFW policy-based mode, navigate to Policy & Objects -> Security Policy, then select Create New. In the policy creation page, the options for Application and URL category will be present.
Important: take note of the following notable behaviors/limitations for these filtering options:
Related documents: Technical Tip: Profile-based policies vs Policy-based policies |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.