In the NSE-7 7.2 EFW study guide it says this:
Although IPS uses flow-based techniques to identify threats but you can apply profile in both flow-based and
proxy-based firewall inspection.
So does attaching an profile turn the rule into a Flow based rule? How can the firewall do both at the same time? In one case the packets are allowed to pass (Flow) and in the other they are help (Proxy). I am just trying to understanding exactly how IPS works with a proxy rule.
Thanks.
Adding an IPS profile to a proxy based rule doesn't turn it to flow based rule.
It searches for attack signatures in flow mode as it does in proxy mode.
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.