In the NSE-7 7.2 EFW study guide it says this:
Although IPS uses flow-based techniques to identify threats but you can apply profile in both flow-based and
proxy-based firewall inspection.
So does attaching an profile turn the rule into a Flow based rule? How can the firewall do both at the same time? In one case the packets are allowed to pass (Flow) and in the other they are help (Proxy). I am just trying to understanding exactly how IPS works with a proxy rule.
Thanks.
Adding an IPS profile to a proxy based rule doesn't turn it to flow based rule.
It searches for attack signatures in flow mode as it does in proxy mode.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.