Hello community, I ran into an article from a source I trust that mention the need of using proxy mode inspection when using the SSL offloading features on the virtual servers. Is this 100% accurate?
I know that SSL DPI is compatible with both proxy and flow. I can't really complete the idea on my mind as to why proxy based is a requirement for that, I know its not the same, but still Im failing to understand. Wanted to see if you FortiExperts out there help me clarifying that.
Hi Kaling
The requirement is not related to SSL DPI, but this is because virtual server itself works only in proxy mode.
Hi,
Yes, your understanding is correct. The requirement is due to the fact that in flow-based approach, which inspects traffic as it passes through, is incompatible with the SSL offloading process that requires full control over the SSL session.
Thanks,
| User | Count |
|---|---|
| 2691 | |
| 1412 | |
| 810 | |
| 710 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.