Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS inspection on a proxy-based policy
In the NSE-7 7.2 EFW study guide it says this:
Although IPS uses flow-based techniques to identify threats but you can apply profile in both flow-based and
proxy-based firewall inspection.
So does attaching an profile turn the rule into a Flow based rule? How can the firewall do both at the same time? In one case the packets are allowed to pass (Flow) and in the other they are help (Proxy). I am just trying to understanding exactly how IPS works with a proxy rule.
Thanks.
Labels:
- Labels:
-
FortiGate
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Adding an IPS profile to a proxy based rule doesn't turn it to flow based rule.
It searches for attack signatures in flow mode as it does in proxy mode.
AEK
AEK
