Course menu

Module 6: Security ProfilesLesson 6.1 (1 of 6 in this module)24 of 33 in the FortiGate Administrator course

Security profiles and inspection modes

What security profiles do, where they attach, flow-based versus proxy-based inspection, and the FortiGuard services behind them.

Intermediate · 10 min read

What you will learn

After this lesson, you can name the main security profiles, attach them to a policy, choose between flow-based and proxy-based inspection, and check that FortiGuard updates are working.

  • Profile types
  • Flow vs proxy
  • FortiGuard
  • Order of checks

A security profile is a set of inspection rules (antivirus, web filter, DNS filter, application control, IPS, file filter and others) attached to an accepting firewall policy. The policy decides whether a session is allowed; its profiles then inspect the content of that allowed traffic and can block, log or modify it. Most profiles depend on FortiGuard signature and rating services.

In simple terms: The policy is the door; the security profiles are the bag check behind it. They only look at traffic the policy has already let in.

A real-life situation

FGT1's LAN-to-Internet policy allows HTTP, HTTPS and DNS. That stops port scans and odd protocols, but nothing about it stops a user downloading malware over HTTPS, visiting a phishing site, or running a peer-to-peer client over port 443. Ports and addresses can't see that. Security profiles look inside the allowed traffic.

The main profiles

ProfileLooks atStops, for example
AntiVirusFiles in web, mail and file transfersKnown malware downloads
Web FilterURLs and their FortiGuard categoryPhishing, malicious and unwanted categories
DNS FilterDNS queries and their categoryLookups for malicious or blocked domains
Application ControlApplication signatures in the trafficPeer-to-peer, proxies and unapproved apps, on any port
IPSExploit and attack signaturesAttacks against clients and servers
File FilterFile typesExecutables or archives leaving or arriving

Every accepting policy also has an SSL/SSH inspection profile. Without decrypting HTTPS (deep inspection), most profiles can only see the server name, not the page or the file. The next lesson is about that choice.

Attaching profiles to a policy

Simplified illustration of the FortiOS 7.4 GUI · not a screenshot
FGT1Policy & Objects › Firewall Policy

Edit Policy: LAN-to-Internet (Security Profiles)

Inspection Mode
Flow-based Proxy-based

Security Profiles

AntiVirus
Ondefault
Web Filter
OnStaff-WF
DNS Filter
Ondefault
Application Control
OnStaff-AppCtrl
IPS
Ondefault
SSL Inspection
certificate-inspectionWithout deep inspection, HTTPS content stays hidden from AV and IPS.
config firewall policy edit 3 set inspection-mode flow set ssl-ssh-profile "certificate-inspection" set av-profile "default" set webfilter-profile "Staff-WF" set dnsfilter-profile "default" set application-list "Staff-AppCtrl" set ips-sensor "default" next end

Profiles are separate objects that policies reference, so one profile can serve many policies. Turning on any profile on a policy also turns on logging of its security events.

Flow-based or proxy-based?

Flow-based (default)Proxy-based
HowInspects packets as they stream through, in a single passBuffers and reassembles content, then inspects it whole
SpeedFaster, lower latency, less memorySlower; the user waits while a file is scanned
FeaturesAll the main profilesExtra options, e.g. some web filter and content features, custom block pages for more protocols
Use forMost trafficWhere a feature you need is proxy-only

Are the signatures current?

Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # diagnose autoupdate versions
AV Engine
---------
Version: 7.00xxx
Contract Expiry Date: ...
Last Updated using scheduled update on ...
Last Update Attempt: ...
Result: No Updates

Virus Definitions
---------
Version: 9x.xxxxx
...

IPS Attack Engine
---------
...
Each engine and database with its version, licence expiry and last update. (Example output, heavily trimmed.) In the GUI: System › FortiGuard shows licence status and lets you trigger an update.

Why it works this way

Inspection is expensive, so the FortiGate does it only for traffic a policy has already accepted, and only with the profiles that policy asks for. That lets you inspect Internet traffic heavily while letting trusted internal traffic pass with little or no inspection.

Common mistakes

  • Turning on antivirus and IPS but leaving SSL inspection at certificate-inspection, then assuming HTTPS downloads are scanned.
  • Adding profiles to the wrong policy: a more specific policy above it handles the traffic without them.
  • Letting the FortiGuard licence expire: profiles keep running on old signatures.
  • No DNS for the FortiGate itself, so ratings and updates fail.

Key takeaways

✅ Key takeaways
  • Security profiles inspect traffic that an accept policy has allowed.
  • Main profiles: antivirus, web filter, DNS filter, application control, IPS, file filter.
  • Flow-based is the fast default; proxy-based buffers content for extra features.
  • FortiGuard keeps signatures current; check with diagnose autoupdate versions.

Check yourself

Predict · scenario 1

Can you add an antivirus profile to a deny policy?

Predict · scenario 2

Which inspection mode buffers a whole file before scanning it?

Predict · scenario 3

A policy has antivirus enabled and SSL inspection set to certificate-inspection. Is malware downloaded over HTTPS caught?

FAQ

Do security profiles work on deny policies?
No. A deny policy drops the session, so there is nothing to inspect. Profiles are only available on policies with action ACCEPT.
Do I need a licence?
The profiles that rely on FortiGuard (antivirus, IPS, web filtering, application signatures beyond the base set) need the matching subscription to stay current. Without it, signatures stop updating and web filter ratings stop working.