Hello everyone,
While I was reading about IPS and how it is being used when in flow based for various security features, such as Antivirus, Web Filtering any many more. What I was intrigued about is the behavior when it is in proxy mode and I found a thread about it, but when I click on it all I see is "This Content was Archived". I can read the first two sentences of the thread from the google search, but it ends right when the person is explaining what happens in proxy based.
Here's the link: https://community.fortinet.com/t5/contentarchivals/contentarchivedpage/message-uid/72266
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
I have unarchived this content. Could you please try again?
Regards,
Hello Ismael,
Could you please give me the title of the article you found on Google please?
If the article has been archived, it is surely because another document related to this topic is existing. I will try to find it for you.
Regards,
Hello Anthony,
The title is
Here's a snapshot as well
I ended up finding the thread by copy pasting the title instead of the two lines under it which sent me to the Archived link for some reason. Just to make sure here the IPS will not be used when in proxy mode contrary to flow based, is that right?
Created on 06-06-2024 02:07 AM Edited on 06-06-2024 02:08 AM
IPS will be used even with proxy-mode inspetion if:
- "inspect all ports" is enabled in protocol options/SSL inspection (IPS is used to identify the protocol and whether wad/proxyy should further be interested in it)
- or if Appcontrol/IPS profiles are included in the policy. (unless you're using new inline feature in 7.4.2+ (link - 959763) .
Hello @Ismael_Awamleh ,
You can review these documents about inspection modes.
https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/969330/proxy-mode-inspection
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/721410/about-inspection-modes
PS
Thank you for providing these links, and I did stumble upon those threads earlier and read them, but they do not specifically compare the behavior of IPS when in flow-based vs proxy-based. Unlike the thread I am looking to read. Unless I missed something, which I would be grateful if you'd highlight it.
Thank you @ozkanaltas
Hello,
I have unarchived this content. Could you please try again?
Regards,
Thank you it works!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.