Hi,
Firewall is in flow mode .
If I change the antivirus inspection mode to proxy mode what is pros and cons
Thanks
Solved! Go to Solution.
You mean I just switch from flow to proxy ? YES Sorry . I did not get the above part . When we do feature switch from Proxy to flow how come the policy ends up with no utm profiles. If you decide to switch back to flow, you have also to update all policies with proxy profiles (e.g. AV) back to flow profiles. The policy will not loose all UTM, only the proxy based profiles, as they are "incompatible" in flow mode.
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi, Not at all, from flow to proxy, you can use profiles in flow or proxy mode. In flow mode, you can only use flow profiles. If you are in proxy mode and have, let's say you have a AV proxy mode profile in a policy, and want to switch back to flow, this policy will loose the AV profile assigned and you have to "manual" select a AV flow profile again. Hope this clarifies it better :)
________________________________________________________
--- NSE 4 ---
________________________________________________________
Exactly... and from 6.4, the proxy/flow mode is selected per policy, yes (you can mix proxy and flow policies)
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi, depends on OS Version. It is always helpfull to tell us your FOS Version at minumum, just for another one. For your question, see https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/100953/inspection-mode-differences-for-a...
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi ,
sorry for that
6.0.6 is the version
Thanks
no prob...
for 6.0.x check https://docs.fortinet.com/document/fortigate/6.0.0/handbook/149549/security-profiles-and-different-m...
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi,
If I want to use proxymode in antivirus profile , do I need to change the firewall mode also to proxy ?
Thanks
Hi, Yes, bevor FOS 6.4, you have to switch the FW to proxy mode. In 6.4 you can decide Flow or Proxy Mode per Policy. You can easily switch to proxy mode, as this is a "more" feature switch. From proxy to flow, you have to check all policies and utm profiles and switch all profiles to flow, otherwise the policy ends up with no (proxy) utm profiles. Best
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi,
Thanks for the reply
Yes, bevor FOS 6.4, you have to switch the FW to proxy mode. In 6.4 you can decide Flow or Proxy Mode per Policy.
You can easily switch to proxy mode, as this is a "more" feature switch.
You mean I just switch from flow to proxy ?
From proxy to flow, you have to check all policies and utm profiles and switch all profiles to flow, otherwise the policy ends up with no (proxy) utm profiles.
Sorry . I did not get the above part . When we do feature switch from Proxy to flow how come the policy ends up with no utm profiles
Currently all my profiles are in flow mode
Thanks
You mean I just switch from flow to proxy ? YES Sorry . I did not get the above part . When we do feature switch from Proxy to flow how come the policy ends up with no utm profiles. If you decide to switch back to flow, you have also to update all policies with proxy profiles (e.g. AV) back to flow profiles. The policy will not loose all UTM, only the proxy based profiles, as they are "incompatible" in flow mode.
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi,
As I understand when we switching from the flow mode we have to change the antivirus profile also to proxy mode
When we switch back we have to change the av profile from proxy to flow mode ?
If yes why a feature change require a profile change also
Thanks
Hi, Not at all, from flow to proxy, you can use profiles in flow or proxy mode. In flow mode, you can only use flow profiles. If you are in proxy mode and have, let's say you have a AV proxy mode profile in a policy, and want to switch back to flow, this policy will loose the AV profile assigned and you have to "manual" select a AV flow profile again. Hope this clarifies it better :)
________________________________________________________
--- NSE 4 ---
________________________________________________________
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.