Security profiles (also called ) are the inspection layer applied to traffic a policy already allowed. They do not replace the policy — they inspect its content.
- AntiVirus — file scanning; flow mode is faster, proxy mode is more accurate.
- — signatures for known attacks and exploits; start in monitor mode, then switch to block.
- Web Filter — blocking by categories (malware, phishing, gambling).
- Application Control — detecting apps like TeamViewer or torrents even on port 443.
- DNS Filter — stops traffic to malicious domains before a connection is even opened.
Certificate vs Deep Inspection
- Certificate inspection — only checks the domain name in the certificate; it cannot see encrypted content.
- Deep inspection — FortiGate decrypts TLS and inspects content; requires installing its CA certificate on the endpoints.