Inspection mode feature comparison
The following table shows which UTM profile can be configured on a flow mode or proxy mode inspection policy.
Some UTM profiles are hidden in the GUI and can only be configured using the CLI. To configure profiles in a firewall policy in CLI, enable the utm-status setting.
Some profiles might have feature differences between flow-based and proxy-based Inspection. From the GUI and CLI, you can set the Feature set option to be Flow-based or Proxy-based to display only the settings for that mode.
Some profiles and features are not supported on FortiGate models with 2 GB RAM or less. See Proxy-related features not supported on FortiGate 2 GB RAM models for the list of models. See also Proxy-based inspection for email protocols supported on models with 2 GB RAM NEW.
|
|
Flow Mode Inspection Policy |
Proxy Mode Inspection Policy |
Feature set option |
||
|---|---|---|---|---|---|
|
UTM Profile |
GUI |
CLI |
GUI |
CLI |
|
|
AntiVirus** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
|
Web Filter** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
|
Video Filter* |
No |
No |
Yes |
Yes |
N/A |
|
DNS Filter*** |
Yes |
Yes |
Yes |
Yes |
N/A |
|
Application Control |
Yes |
Yes |
Yes |
Yes |
N/A |
|
Inline CASB* |
No |
No |
Yes |
Yes |
N/A |
|
Intrusion Prevention System |
Yes |
Yes |
Yes |
Yes |
N/A |
|
File Filter** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
|
Email Filter** |
Yes |
Yes |
Yes |
Yes |
GUI/CLI |
|
VoIP |
Yes |
Yes |
Yes |
Yes |
N/A |
|
ICAP* |
No |
No |
Yes |
Yes |
N/A |
|
Web Application Firewall* |
No |
No |
Yes |
Yes |
N/A |
|
Data Loss Prevention** |
No |
Yes |
Yes |
Yes |
CLI |
|
Virtual Patching |
Yes |
Yes |
Yes |
Yes |
N/A |
|
SSL/SSH Inspection |
Yes |
Yes |
Yes |
Yes |
N/A |
|
SSH Filter* |
No |
No |
No |
Yes |
N/A |
* Proxy-only UTM profiles are not supported on FortiGate models with 2 GB RAM or less.
** Feature set option is not available on FortiGate models with 2 GB RAM or less. Profile only supports flow mode.
*** The transparent conditional DNS forwarder feature only works with a proxy-based firewall policy. The feature uses DNS filters with transparent-dns-database enabled and is not available on FortiGate models with 2 GB RAM or less.
The following sections outline differences between flow-based and proxy-based inspection for a security profile.
Feature comparison between Antivirus inspection modes
The following table indicates which Antivirus features are supported by their designated scan modes.
|
Part1 |
Replacement Message |
Content Disarm |
Mobile Malware |
Virus Outbreak |
Sandbox Post-Transfer Scanning |
Sandbox Inline Scanning |
NAC Quarantine |
|---|---|---|---|---|---|---|---|
|
Proxy (2) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Flow |
Yes (1) |
No |
Yes |
Yes |
Yes |
Yes |
Yes |
-
IPS Engine caches the URL and a replacement message is presented after the second attempt.
-
Not available on FortiGate models with 2 GB RAM or less, except when the firewall policy inspects email protocols SMTP(s), POP3(s), IMAP(s), and NNTP.
|
Part 2 |
Archive Blocking |
Emulator |
Client Comforting |
Infection Quarantine |
Heuristics |
Treat EXE as Virus |
|---|---|---|---|---|---|---|
|
Proxy (3) |
Yes |
Yes |
Yes |
Yes (1) |
Yes |
Yes (2) |
|
Flow |
Yes |
Yes |
No |
Yes (1) |
Yes |
Yes (2) |
-
Only available on FortiGate models with HDD or when FortiAnalyzer or FortiGate Cloud is connected and enabled.
-
Only applies to inspection on IMAP, POP3, SMTP, and MAPI protocols.
-
Not available on FortiGate models with 2 GB RAM or less, except when the firewall policy inspects email protocols SMTP(s), POP3(s), IMAP(s), and NNTP.
|
Part 3 |
External Blocklist |
EMS External Feed |
AI/ML Based Detection |
FortiNDR Inline Detection |
|---|---|---|---|---|
|
Proxy (1) |
Yes |
Yes |
Yes |
Yes |
|
Flow |
Yes |
Yes |
Yes |
No |
-
Not available on FortiGate models with 2 GB RAM or less, except when the firewall policy inspects email protocols SMTP(s), POP3(s), IMAP(s), and NNTP.
Feature comparison between Web Filter inspection modes
The following table indicates which Web Filter features are supported by their designated inspection modes.
|
|
FortiGuard Category-Based Filter |
Category Usage Quota |
Override Blocked Categories |
Search Engines |
Static URL Filter |
Rating Option |
Proxy Option |
Web Profile Override |
|---|---|---|---|---|---|---|---|---|
|
Proxy (4) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Flow |
Yes (1) |
No |
Yes (2) |
Yes |
Yes (5) |
Yes |
Limited (3) |
No |
-
Local Category and Remote Category filters do not support the warning and authenticate actions.
-
Local Category and Remote Category filters cannot be overridden.
-
Only HTTP POST Action and Remove Cookies are supported.
-
Not available on FortiGate models with 2 GB RAM or less.
-
File filter is not supported. See Configuring web filter to exempt URLs from other security profiles.
Feature comparison between Email Filter inspection modes
The following tables indicate which Email Filters are supported by the specified inspection modes for local filtering and FortiGuard-assisted filtering.
|
Local Filtering |
Banned Word Check |
Block/Allow List |
HELO/ EHLO DNS Check |
Return Address DNS Check |
DNSBL/ ORBL Check |
MIME Header Check |
|---|---|---|---|---|---|---|
|
Proxy |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Flow |
Yes |
Yes |
No |
No |
No |
Yes |
|
FortiGuard-Assisted Filtering |
Phishing URL Check |
Anti-Spam IP Check |
Submit Spam to FortiGuard |
Spam Email Checksum Check |
Spam URL Check |
|---|---|---|---|---|---|
|
Proxy |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Flow |
No |
No |
No |
No |
No |
Feature comparison between DLP inspection modes
The following table indicates which DLP filters are supported by their designated inspection modes.
|
|
Credit Card Filter |
SSN Filter |
Regex Filter |
File-Type Filter |
File-Pattern Filter |
Fingerprint Filter |
Watermark Filter |
Encrypted Filter |
File-Size Filter |
|---|---|---|---|---|---|---|---|---|---|
|
Proxy (2) |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Flow |
Yes |
Yes |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes (1) |
-
File-size filtering only works if file size is present in the protocol exchange.
-
Not available on FortiGate models with 2 GB RAM or less, except when the firewall policy inspects email protocols SMTP(s), POP3(s), IMAP(s), and NNTP.
|
|
Inspection of SMBv3 multichannel is not supported. To inspect SMBv3 traffic, it is advisable to disable multichannel support first. See the vendor specific documentation for more information on disabling multichannel support. |