Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DavidTrevor
New Contributor

Benefits of using proxy policies vs firewall policies?

Currently we are using a FortiGate with explicit proxy in our environment because we have always used a proxy in the past to control which users get access to the internet and which do not. The same FortiGate is also the main firewall and default gateay. On the proxy policies, we use the following security features:

- SSL Deep Inspection

- Antivirus

- Web Filter

- Application Control

- File Filter

 

The clients get the proxy information via PAC file. However, the proxy address is the same as our default gateway, which means internet connection could be established over normal IPv4 firewall policies as well. From time to time, there is problems with websites or applications that do not go over the proxy correctly. Either there is a problem with authentication (407 Authentication Required) or the websites simply break as soon as any security profile is applied (i.e. the browser returns err_emtpy_response).

 

That makes me wonder, aside from the user authentication part, are there any benefits of using a proxy in our environment? As far as I can tell, I can also apply SSL Deep Inspection and all the other security profiles (Antivirus etc...) to a normal IPv4 policy, can I not?

1 Solution
metz_FTNT
Staff
Staff

Hi David,

 

The major benefit of explicit proxy is indeed the user authentication. 

Aside of that, you might want to use explicit proxy if you want to completely deny the client PCs direct access to Internet, so they can only have access to the proxy server. 

 

You can have all the UTM features on IPv4 policies.

 

Regardless, "err_emtpy_response" message should not occur neither on explicit proxy nor IPv4 policy, this has to be investigated and resolved. 

 

There were also some bugs which can cause this error, if you are on an old firmware, you might want to try to upgrade and see if it will be resolved.

 

 

View solution in original post

4 REPLIES 4
metz_FTNT
Staff
Staff

Hi David,

 

The major benefit of explicit proxy is indeed the user authentication. 

Aside of that, you might want to use explicit proxy if you want to completely deny the client PCs direct access to Internet, so they can only have access to the proxy server. 

 

You can have all the UTM features on IPv4 policies.

 

Regardless, "err_emtpy_response" message should not occur neither on explicit proxy nor IPv4 policy, this has to be investigated and resolved. 

 

There were also some bugs which can cause this error, if you are on an old firmware, you might want to try to upgrade and see if it will be resolved.

 

 

DavidTrevor

Thanks for your helpful reply! We are on 6.4.9 but plan to upgrade to 7.X soon. Any recommended version we should upgrade to?

 

Also I have read somewhere that the proxy offers caching compared to normal IPv4 policies, does that still apply or is it outdated information?

metz_FTNT

Web caching is possible in both explicit proxy or IPv4 policies.

 

6.4.11 or 7.0.8, both should be fine. 

 

Sheikh
Staff
Staff

Hi,

 

as mentioned by @metz_FTNT earlier, in Proxy authentication you can set methods in "Authentication schemes" like Basic, Certificate based, Digest, Form Based, FSSO, NTLM, SAML Radius Single Sign-on etc..

 

You can also configure a Keytab file to get Kerberos authentication which is available with "Negotiate" method.

 

regards,

 

Sheikh

 

 

 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Labels
Top Kudoed Authors