Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kailing
New Contributor

SSL Offloading proxy vs flow

Hello community, I ran into an article from a source I trust that mention the need of using proxy mode inspection when using the SSL offloading features on the virtual servers. Is this 100% accurate?

I know that SSL DPI is compatible with both proxy and flow. I can't really complete the idea on my mind as to why proxy based is a requirement for that, I know its not the same, but still Im failing to understand. Wanted to see if you FortiExperts out there help me clarifying that.

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Kaling

The requirement is not related to SSL DPI, but this is because virtual server itself works only in proxy mode.

AEK
AEK
Atul_S
Staff & Editor
Staff & Editor

Hi,

 

Yes, your understanding is correct. The requirement is due to the fact that in flow-based approach, which inspects traffic as it passes through, is incompatible with the SSL offloading process that requires full control over the SSL session.

 

Thanks,

Atul Srivastava
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors