A real-life situation
FGT1's LAN-to-Internet policy allows HTTP, HTTPS and DNS. That stops port scans and odd protocols, but nothing about it stops a user downloading malware over HTTPS, visiting a phishing site, or running a peer-to-peer client over port 443. Ports and addresses can't see that. Security profiles look inside the allowed traffic.
The main profiles
| Profile | Looks at | Stops, for example |
|---|---|---|
| AntiVirus | Files in web, mail and file transfers | Known malware downloads |
| Web Filter | URLs and their FortiGuard category | Phishing, malicious and unwanted categories |
| DNS Filter | DNS queries and their category | Lookups for malicious or blocked domains |
| Application Control | Application signatures in the traffic | Peer-to-peer, proxies and unapproved apps, on any port |
| IPS | Exploit and attack signatures | Attacks against clients and servers |
| File Filter | File types | Executables or archives leaving or arriving |
Every accepting policy also has an SSL/SSH inspection profile. Without decrypting HTTPS (deep inspection), most profiles can only see the server name, not the page or the file. The next lesson is about that choice.
Attaching profiles to a policy
Edit Policy: LAN-to-Internet (Security Profiles)
- Inspection Mode
- Flow-based Proxy-based
- AntiVirus
- Ondefault
- Web Filter
- OnStaff-WF
- DNS Filter
- Ondefault
- Application Control
- OnStaff-AppCtrl
- IPS
- Ondefault
- SSL Inspection
- certificate-inspectionWithout deep inspection, HTTPS content stays hidden from AV and IPS.
Security Profiles
config firewall policy
edit 3
set inspection-mode flow
set ssl-ssh-profile "certificate-inspection"
set av-profile "default"
set webfilter-profile "Staff-WF"
set dnsfilter-profile "default"
set application-list "Staff-AppCtrl"
set ips-sensor "default"
next
endProfiles are separate objects that policies reference, so one profile can serve many policies. Turning on any profile on a policy also turns on logging of its security events.
Flow-based or proxy-based?
| Flow-based (default) | Proxy-based | |
|---|---|---|
| How | Inspects packets as they stream through, in a single pass | Buffers and reassembles content, then inspects it whole |
| Speed | Faster, lower latency, less memory | Slower; the user waits while a file is scanned |
| Features | All the main profiles | Extra options, e.g. some web filter and content features, custom block pages for more protocols |
| Use for | Most traffic | Where a feature you need is proxy-only |
Are the signatures current?
FGT1 # diagnose autoupdate versions AV Engine --------- Version: 7.00xxx Contract Expiry Date: ... Last Updated using scheduled update on ... Last Update Attempt: ... Result: No Updates Virus Definitions --------- Version: 9x.xxxxx ... IPS Attack Engine --------- ...
Why it works this way
Inspection is expensive, so the FortiGate does it only for traffic a policy has already accepted, and only with the profiles that policy asks for. That lets you inspect Internet traffic heavily while letting trusted internal traffic pass with little or no inspection.
Common mistakes
- Turning on antivirus and IPS but leaving SSL inspection at certificate-inspection, then assuming HTTPS downloads are scanned.
- Adding profiles to the wrong policy: a more specific policy above it handles the traffic without them.
- Letting the FortiGuard licence expire: profiles keep running on old signatures.
- No DNS for the FortiGate itself, so ratings and updates fail.
Key takeaways
- Security profiles inspect traffic that an accept policy has allowed.
- Main profiles: antivirus, web filter, DNS filter, application control, IPS, file filter.
- Flow-based is the fast default; proxy-based buffers content for extra features.
- FortiGuard keeps signatures current; check with diagnose autoupdate versions.
Check yourself
Can you add an antivirus profile to a deny policy?
Which inspection mode buffers a whole file before scanning it?
A policy has antivirus enabled and SSL inspection set to certificate-inspection. Is malware downloaded over HTTPS caught?