Skip to main content
AD Academy
Network security: Fortinet
Intermediate16 minLast updated: Topic 7 of 14

Security profiles and SSL inspection

AntiVirus, IPS, web filter, application control and Certificate vs Deep Inspection.

Not read

What you will learn here

  • What AntiVirus, IPS and Web Filter do
  • What Application Control is
  • Certificate vs Deep Inspection

Worth reading first:VPN: IPsec site-to-site and SSL VPN

Security profiles (also called ) are the inspection layer applied to traffic a policy already allowed. They do not replace the policy — they inspect its content.

  • AntiVirus — file scanning; flow mode is faster, proxy mode is more accurate.
  • — signatures for known attacks and exploits; start in monitor mode, then switch to block.
  • Web Filter — blocking by categories (malware, phishing, gambling).
  • Application Control — detecting apps like TeamViewer or torrents even on port 443.
  • DNS Filter — stops traffic to malicious domains before a connection is even opened.

Certificate vs Deep Inspection

  • Certificate inspection — only checks the domain name in the certificate; it cannot see encrypted content.
  • Deep inspection — FortiGate decrypts TLS and inspects content; requires installing its CA certificate on the endpoints.

Check yourself

Why is deep inspection needed?

Was this page helpful?