Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sims
New Contributor III

Inspection mode

Hi,

Firewall is in   flow mode .

If I change the antivirus inspection mode to proxy mode what is pros and cons 

Thanks 

 

3 Solutions
Markus
Valued Contributor

You mean I just switch  from  flow to proxy ? YES Sorry . I did not get the above part . When we do feature switch  from Proxy to flow  how come the policy ends up with  no utm profiles. If you decide to switch back to flow, you have also to update all policies with proxy profiles (e.g. AV) back to flow profiles. The policy will not loose all UTM, only the proxy based profiles, as they are "incompatible" in flow mode.


________________________________________________________
--- NSE 4 ---
________________________________________________________

View solution in original post

________________________________________________________--- NSE 4 ---________________________________________________________
Markus
Valued Contributor

Hi, Not at all, from flow to proxy, you can use profiles in flow or proxy mode. In flow mode, you can only use flow profiles. If you are in proxy mode and have, let's say you have a AV proxy mode profile in a policy, and want to switch back to flow, this policy will loose the AV profile assigned and you have to "manual" select a AV flow profile again. Hope this clarifies it better :)


________________________________________________________
--- NSE 4 ---
________________________________________________________

View solution in original post

________________________________________________________--- NSE 4 ---________________________________________________________
Markus
Valued Contributor

Exactly... and from 6.4, the proxy/flow mode is selected per policy, yes (you can mix proxy and flow policies)

 

 


________________________________________________________
--- NSE 4 ---
________________________________________________________

View solution in original post

________________________________________________________--- NSE 4 ---________________________________________________________
11 REPLIES 11
Markus
Valued Contributor

Hi, depends on OS Version. It is always helpfull to tell us your FOS Version at minumum, just for another one. For your question, see https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/100953/inspection-mode-differences-for-a...

 


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
sims
New Contributor III

Hi ,

sorry for that 

6.0.6 is the version 

 

Thanks

 

Markus
Valued Contributor

no prob...

for 6.0.x check https://docs.fortinet.com/document/fortigate/6.0.0/handbook/149549/security-profiles-and-different-m...

 


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
sims
New Contributor III

Hi,

If I want to use proxymode in antivirus profile , do  I need to  change the firewall mode also to proxy ? 

Thanks

Markus
Valued Contributor

Hi, Yes, bevor FOS 6.4, you have to switch the FW to proxy mode. In 6.4 you can decide Flow or Proxy Mode per Policy. You can easily switch to proxy mode, as this is a "more" feature switch. From proxy to flow, you have to check all policies and utm profiles and switch all profiles to flow, otherwise the policy ends up with no (proxy) utm profiles. Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
sims
New Contributor III

Hi,

 

 

Thanks for the reply  

 

Yes, bevor FOS 6.4, you have to switch the FW to proxy mode. In 6.4 you can decide Flow or Proxy Mode per Policy.

 

You can easily switch to proxy mode, as this is a "more" feature switch.

 

You mean I just switch  from  flow to proxy ?

 

From proxy to flow, you have to check all policies and utm profiles and switch all profiles to flow, otherwise the policy ends up with no (proxy) utm profiles.

 

Sorry . I did not get the above part . When we do feature switch  from Proxy to flow  how come the policy ends up with  no utm profiles

 

Currently all my profiles are in flow  mode

 

Thanks

 

 

Markus
Valued Contributor

You mean I just switch  from  flow to proxy ? YES Sorry . I did not get the above part . When we do feature switch  from Proxy to flow  how come the policy ends up with  no utm profiles. If you decide to switch back to flow, you have also to update all policies with proxy profiles (e.g. AV) back to flow profiles. The policy will not loose all UTM, only the proxy based profiles, as they are "incompatible" in flow mode.


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
sims
New Contributor III

Hi,

 

As I understand when we switching  from the  flow mode we have to change the antivirus profile also to  proxy mode

When we switch back we have to change the av profile  from proxy to flow mode ?

If yes  why a feature change require  a profile change also

 

Thanks

 

 

 

 

 

 

 

 

Markus
Valued Contributor

Hi, Not at all, from flow to proxy, you can use profiles in flow or proxy mode. In flow mode, you can only use flow profiles. If you are in proxy mode and have, let's say you have a AV proxy mode profile in a policy, and want to switch back to flow, this policy will loose the AV profile assigned and you have to "manual" select a AV flow profile again. Hope this clarifies it better :)


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors