Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sfales
New Contributor II

Flow vs Proxy Webfilter

I just upgraded a couple of units from MR2p8 to MR3p5. I' m working through the differences, but had a question about Webfiltering. As the new version has a choice for Flow vs. Proxy, I' m trying to decide what will work best for me. I know this has always been a choice for A/V. With A/V I use flow at branch offices and Proxy at Datacenters. Any opinions on Best practices? TIA, Scott
(4) - 200b' s (15) 81WiFi FAZ 400b Fmgr 100c
(4) - 200b' s (15) 81WiFi FAZ 400b Fmgr 100c
7 REPLIES 7
kdyck
New Contributor

Here' s another post asking the same thing. http://support.fortinet.com/forum/tm.asp?m=78640&appid=&p=&mpage=1&key=inspection%2Cmode&language=single&tmode=&smode=&s=#78640 It might offer some insight.
FortiRack_Eric
New Contributor III

Rule of thumb for bigger and more loaded boxes ==> AV flow based For webfiltering use flow were possible. Bear in mind that you don' t have the monitor and the override option. Did some tuning on a 3140B doing approx 750 Mb and changing the AV profiles from proxy to flow an decrease of CPU of 20-25% and memory 30% decrease.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
sfales

Thanks for the links and info. This is helpful information. I understand the whole proxy vs flow from an AV standpoint. This makes sense about how it scans the traffic passing thru it. I don' t understand proxy vs flow from a web-filtering standpoint. Isn' t the FG just comparing destination URLs to a database of known URLs? (am I over thinking this?) Eric - Your racks look good! I might need to pick up a couple! Thanks, Scott
(4) - 200b' s (15) 81WiFi FAZ 400b Fmgr 100c
(4) - 200b' s (15) 81WiFi FAZ 400b Fmgr 100c
FortiRack_Eric

Eric - Your racks look good! I might need to pick up a couple! Thanks, Scott
Thanks Scott, Thank god I' m not a girl. You can contact Fine Tec Computer in the US they have them on stock! Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
veechee
New Contributor

I' m interested as well in how the web filter differs between proxy and flow-based. I' ve never found web browsing speed to be an issue, and I experimented with flow-based web filtering when I first upgraded to 4.3, but I couldn' t tell that it worked at all. I tried some sites that I knew were blocked and they displayed no problem. So I' ve stuck to proxy-based since then.
bmann
New Contributor

from manual: Proxy-based detection involves buffering the file and examining it as a whole. Advantages of proxy-based detection include a more thorough examination of attachments, especially archive formats and nesting. Flow-based detection examines the file as it passes through the FortiGate unit without any buffering. Advantages of flow-based detection include speed and no interruption of detection during conserve mode.
veechee
New Contributor

bmann, What you posted sounds like the description for flow vs proxy AV mode. But what about web filtering?
Labels
Top Kudoed Authors