Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
armagandarilmaz
New Contributor

Why does application control use flow based inspection mode?

Hi,

 

I really wonder why application control uses flow-based inspection rather than proxy-based. Is there anyone to explain that or share some documents related to that.

4 REPLIES 4
bommi
Contributor III

Application control is build on top of the ips-engine and the ips-engine itself is flow-mode only.

NSE 4/5/7

NSE 4/5/7
armagandarilmaz

Okay I know that, but is there any specific reason to do that? Can the reason is that flow-based doesn’t operate using built-in protocol states?

tanr
Valued Contributor II

A good overview is "Life of a Packet" - http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-life-of-packet/LOP_intro.htm, especially the sections on UTM/NGFW packet flow for flow-based and proxy-based inspection.

 

armagandarilmaz

Thank you for your help.

Labels
Top Kudoed Authors