Inspection mode feature comparison
The following table shows which UTM profile can be configured on a flow mode or proxy mode inspection policy.
Some UTM profiles are hidden in the GUI and can only be configured using the CLI. To configure profiles in a firewall policy in CLI, enable the utm-status
setting.
Some profiles might have feature differences between flow-based and proxy-based Inspection. From the GUI and CLI, you can set the Feature set option to be Flow-based or Proxy-based to display only the settings for that mode.
Some profiles and features are not supported on FortiGate models with 2 GB RAM or less. See Proxy-related features not supported on FortiGate 2 GB RAM models for the list of models.
|
Flow Mode Inspection Policy |
Proxy Mode Inspection Policy |
Feature set option |
||
---|---|---|---|---|---|
UTM Profile |
GUI |
CLI |
GUI |
CLI |
|
AntiVirus** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
Web Filter** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
Video Filter* |
No |
No |
Yes |
Yes |
N/A |
DNS Filter*** |
Yes |
Yes |
Yes |
Yes |
N/A |
Application Control |
Yes |
Yes |
Yes |
Yes |
N/A |
Inline CASB* |
No |
No |
Yes |
Yes |
N/A |
Intrusion Prevention System |
Yes |
Yes |
Yes |
Yes |
N/A |
File Filter** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
Email Filter** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
VoIP |
Yes |
Yes |
Yes |
Yes |
N/A |
ICAP* |
No |
No |
Yes |
Yes |
N/A |
Web Application Firewall* |
No |
No |
Yes |
Yes |
N/A |
Data Loss Prevention** |
No |
Yes |
Yes |
Yes |
CLI |
Virtual Patching |
Yes |
Yes |
Yes |
Yes |
N/A |
SSL/SSH Inspection |
Yes |
Yes |
Yes |
Yes |
N/A |
SSH Filter* |
No |
No |
No |
Yes |
N/A |
* Proxy-only UTM profiles are not supported on FortiGate models with 2 GB RAM or less.
** Feature set option is not available on FortiGate models with 2 GB RAM or less. Profile only supports flow mode.
*** The transparent conditional DNS forwarder feature only works with a proxy-based firewall policy. The feature uses DNS filters with transparent-dns-database
enabled and is not available on FortiGate models with 2 GB RAM or less.
The following sections outline differences between flow-based and proxy-based inspection for a security profile.
Feature comparison between Antivirus inspection modes
The following table indicates which Antivirus features are supported by their designated scan modes.
Part1 |
Replacement Message |
Content Disarm |
Mobile Malware |
Virus Outbreak |
Sandbox Post-Transfer Scanning |
Sandbox Inline Scanning |
NAC Quarantine |
---|---|---|---|---|---|---|---|
Proxy (2) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Flow |
Yes (1) |
No |
Yes |
Yes |
Yes |
No |
Yes |
-
IPS Engine caches the URL and a replacement message is presented after the second attempt.
-
Not available on FortiGate models with 2 GB RAM or less.
Part 2 |
Archive Blocking |
Emulator |
Client Comforting |
Infection Quarantine |
Heuristics |
Treat EXE as Virus |
---|---|---|---|---|---|---|
Proxy (3) |
Yes |
Yes |
Yes |
Yes (1) |
Yes |
Yes (2) |
Flow |
Yes |
Yes |
No |
Yes (1) |
Yes |
Yes (2) |
-
Only available on FortiGate models with HDD or when FortiAnalyzer or FortiGate Cloud is connected and enabled.
-
Only applies to inspection on IMAP, POP3, SMTP, and MAPI protocols.
-
Not available on FortiGate models with 2 GB RAM or less.
Part 3 |
External Blocklist |
EMS Threat Feed |
AI/ML Based Detection |
FortiNDR Inline Detection |
---|---|---|---|---|
Proxy (1) |
Yes |
Yes |
Yes |
Yes |
Flow |
Yes |
Yes |
Yes |
No |
-
Not available on FortiGate models with 2 GB RAM or less.
Feature comparison between Web Filter inspection modes
The following table indicates which Web Filter features are supported by their designated inspection modes.
|
FortiGuard Category-Based Filter |
Category Usage Quota |
Override Blocked Categories |
Search Engines |
Static URL Filter |
Rating Option |
Proxy Option |
Web Profile Override |
---|---|---|---|---|---|---|---|---|
Proxy (4) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Flow |
Yes (1) |
No |
Yes (2) |
Yes |
Yes |
Yes |
Limited (3) |
No |
-
Local Category and Remote Category filters do not support the warning and authenticate actions.
-
Local Category and Remote Category filters cannot be overridden.
-
Only HTTP POST Action and Remove Cookies are supported.
-
Not available on FortiGate models with 2 GB RAM or less.
Feature comparison between Email Filter inspection modes
The following tables indicate which Email Filters are supported by the specified inspection modes for local filtering and FortiGuard-assisted filtering.
Local Filtering |
Banned Word Check |
Block/Allow List |
HELO/ EHLO DNS Check |
Return Address DNS Check |
DNSBL/ ORBL Check |
MIME Header Check |
---|---|---|---|---|---|---|
Proxy (1) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Flow |
Yes |
Yes |
No |
No |
No |
Yes |
-
Not available on FortiGate models with 2 GB RAM or less
FortiGuard-Assisted Filtering |
Phishing URL Check |
Anti-Spam IP Check |
Submit Spam to FortiGuard |
Spam Email Checksum Check |
Spam URL Check |
---|---|---|---|---|---|
Proxy (1) |
Yes |
Yes |
Yes |
Yes |
Yes |
Flow |
No |
No |
No |
No |
No |
-
Not available on FortiGate models with 2 GB RAM or less
Feature comparison between DLP inspection modes
The following table indicates which DLP filters are supported by their designated inspection modes.
|
Credit Card Filter |
SSN Filter |
Regex Filter |
File-Type Filter |
File-Pattern Filter |
Fingerprint Filter |
Watermark Filter |
Encrypted Filter |
File-Size Filter |
---|---|---|---|---|---|---|---|---|---|
Proxy (2) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Flow |
Yes |
Yes |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes (1) |
-
File-size filtering only works if file size is present in the protocol exchange.
-
Not available on FortiGate models with 2 GB RAM or less.