FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
sreddi
Staff
Staff
Article Id 195726

Description
To more clearly show the features specific to proxy-based mode, use the new feature set option to select 'Flow-based' or 'Proxy-based'.
When 'Flow-based' or 'Proxy-based' are selected, only the features for that mode are available.

This article describes these features.

Solution
The following pages have the Feature set option.

- Security Profiles -> AntiVirus.
- Security Profiles -> Web Filter.
- Security Profiles -> Email Filter.
- Security Profiles -> Data Leak (CLI only).
- Policy & Objects -> Protocol Options.

Example of the Feature set option in Security Profiles  -> AntiVirus.



 
 
 
If 'Proxy-based' is selected, a red 'P' icon indicates the proxy-only features.
 
 
 
 
When firewall policies are configured.

- If the inspection mode is flow-based, dropdown menus only display profile with flow-based feature sets.
- If the inspection mode is proxy-based, dropdown menus display profiles with flow-based or proxy-based feature sets.

If a flow-based inspection policy has a proxy-based profile assigned, a warning icon and tooltip informs that proxy features do not work in a flow-based policy.
This warning also appears when  the CLI is used to assign security profiles.