Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
harald21
Contributor

Questions about proxy-based vs. flow-based av scanning

Hello, I have some questions about proxy-based vs. flow-based av scanning and hope you can help me: 1. Is it possible to use flow-based and proxy-based av profiles on one FortiGate device at the same time? 2. When I try to test this I get the error message " The flow-based AntiVirus database is not available when the extended AntiVirus database is in use." Does anybody know if it is planned to support this in a future release? 3. Does anybody know what are the differences between normal and extended ips database? (documentation just states that these two databases exist, but not what the differences are) Sincerely Harald
2 REPLIES 2
netmin
Contributor II

Hello Harald, we haven' t used both variants due to potential false positives using 5.0.x flow-based inspection, but since it is configured at the profile level I would assume so. re 2: this is mentioned in the 5.2.0 what' s new guide in addition to an improved flow-based AV scanning technology, that is advertised as to detect viruses as accurate as proxy-based inspection re 3: in 5.0.x, we found categories like " Web.Others" (i.e. web browser type detection) being available in the extended package.
Sean_Toomey_FTNT

There are significant improvements to flow antivirus in FortiOS 5.2 and it is as good (or nearly so) than proxy antivirus now. To answer your questions: 1. Technically, yes you can, but not on the same rule. 2. At least on FortiOS 5.2, the default is the extended DB and yes it is supported with flow mode 3. From the FortiOS Handbook: In most circumstances, the regular virus database provides sufficient protection. Viruses known to be active are included in the regular virus database. The extended database includes signatures of the viruses that have become rare within the last year in addition to those in the normal database. The extreme database includes legacy viruses that have not been seen in the wild in a long time in addition to those in the extended database. Now while you *can* have proxy and flow profiles on different rules in the same policy, it is best practice not to mix flow and proxy profiles. In 5.0 the decision was harder but in 5.2 my solid recommendation for most environments is to use flow mode. Flow mode takes far less resources on the box and not having to use proxy means fewer moving parts (less chance for things to go wrong) and also you no longer have to worry about size limitations of the file to be scanned. Hope this helps. Cheers!
-- Sean Toomey, CISSP FCNSP Consulting Security Engineer (CSE) FORTINET— High Performance Network Security
Labels
Top Kudoed Authors