Standard Layer 3 and Layer 4 firewall policies filter traffic based strictly on source IP, destination IP, protocol, and port. While this stateful inspection controls basic network access, it cannot protect your internal users against malicious web destinations, drive-by malware downloads, or evasive application-layer threats. Applying FortiGate security profiles to your firewall policies upgrades basic packet filtering into full Layer 7 Next-Generation Firewall (NGFW) threat inspection.

In this technical tutorial, you will learn how to build, tune, and attach FortiGate security profiles—including Antivirus, Web Filtering, Application Control, Intrusion Prevention System (IPS), and SSL Inspection—to outbound firewall policies. We will also examine packet processing flows, verification procedures, and step-by-step troubleshooting workflows.

Real-Life Scenario

Acme Corporation needs to secure Internet access for its office workers on the internal network. The enterprise permits outbound web traffic, but corporate compliance demands multi-layered security controls:

  • Antivirus: Block malicious payload downloads over HTTP, HTTPS, and FTP.
  • Web Filtering: Block access to known phishing, malware distribution, adult, and high-risk domain categories. Enforce safe searching.
  • Application Control: Block high-risk applications, peer-to-peer (P2P) file sharing, and anonymizing proxies, regardless of port numbers used.
  • Intrusion Prevention (IPS): Block client-side exploits and command-and-control (C2) botnet traffic.
  • SSL Inspection: Decrypt outbound HTTPS sessions so the inspection engines can examine encrypted payloads.

Lab Topology

The following diagram shows the lab network topology used in this configuration guide.

 [ Internal Hosts ]
  (10.0.1.0/24)
        |
 [ port2: 10.0.1.1 ] (LAN Interface)
+------------------------------------------------+
|         FortiGate Firewall (FortiOS)           |
|                                                |
| Security Profiles Applied:                     |
|  - Antivirus Profile                           |
|  - Web Filter Profile                          |
|  - Application Control Profile                 |
|  - IPS Sensor                                  |
|  - SSL/SSH Inspection Profile                  |
+------------------------------------------------+
 [ port1: 198.51.100.2/24 ] (WAN Interface)
        |
 [ Next-Hop ISP Router: 198.51.100.1 ]
        |
   ( Internet )

Example Addressing and Objects

The table below details the interfaces, network address objects, and security profile names used throughout this guide. All IP addresses represent example/lab assignments.

Object / Item Name Type Example Value Purpose
port1 Physical Interface 198.51.100.2/24 (GW: 198.51.100.1) WAN egress interface connecting to ISP (EXAMPLE)
port2 Physical Interface 10.0.1.1/24 LAN ingress interface connecting to internal hosts (EXAMPLE)
LAB_LAN_Subnet Address Object 10.0.1.0/24 Subnet object representing internal corporate users
AV_Profile_Outbound Antivirus Profile Flow-based AV Engine Inspects downloads for viruses and ransomware signatures
WF_Profile_Outbound Web Filter Profile Category Blocking & URL Filter Restricts access to malicious and inappropriate web content
AC_Profile_Outbound Application Control Profile App Signatures & Categories Blocks P2P, tunnelers, and unapproved web services
IPS_Profile_Outbound IPS Sensor Client Security Signatures Detects and blocks client-side exploits and C2 callouts
SSL_Deep_Inspection SSL/SSH Profile Deep Inspection (Custom CA) Decrypts encrypted SSL/TLS traffic for inspection engines

Prerequisites

  • Active Subscriptions: Active FortiGuard security subscriptions for Antivirus, Web Filtering, Application Control, and IPS.
  • Routing and Connectivity: Pre-existing layer 3 routing and IP connectivity between the LAN and WAN.
  • CA Certificate Installation: If using Deep SSL Inspection, the FortiGate CA certificate (or an enterprise Subordinate CA signed by your internal PKI) must be deployed to client browsers and trust stores via GPO, MDM, or manual installation.
  • FortiOS Version Context: Note that exact GUI menu locations and CLI parameters may vary slightly depending on your FortiOS release (such as 7.0, 7.2, or 7.4) and platform feature visibility settings.

Step-by-Step GUI Configuration

Step 1: Verify FortiGuard Entitlements

Navigate to System > FortiGuard in the FortiGate GUI. Confirm that the status for AntiVirus, Web Filter, Application Control, and Intrusion Prevention displays an active license indicator. If signatures are outdated, click Update Antivirus Definitions and Update Engine & IPS Definitions.

Step 2: Configure the Antivirus Profile

Navigate to Security Profiles > Antivirus.

  1. Click Create New.
  2. Set Name to AV_Profile_Outbound.
  3. Select Flow-based or Proxy-based inspection mode depending on your system strategy (Flow mode offers higher throughput; Proxy mode offers complete payload buffering).
  4. Enable scanning for HTTP, FTP, SFTP, and email protocols as required.
  5. Enable FortiSandbox Inspection if an integrated FortiSandbox appliance or cloud service is available.
  6. Click Apply.

Step 3: Configure the Web Filter Profile

Navigate to Security Profiles > Web Filter.

  1. Click Create New.
  2. Set Name to WF_Profile_Outbound.
  3. Under FortiGuard Category Based Filter, enable the feature.
  4. Expand categories and set sensitive or dangerous groups (e.g., Potentially Liable, Security Risk, Adult Material) to Block.
  5. Under Static URL Filter, enable URL Filter options if specific explicit site blocks or overrides are required.
  6. Enable Search Engines > Enforce SafeSearch on supported search providers if required.
  7. Click Apply.

Step 4: Configure the Application Control Profile

Navigate to Security Profiles > Application Control.

  1. Click Create New.
  2. Set Name to AC_Profile_Outbound.
  3. In the Categories table, locate high-risk application groups such as P2P and Proxy, right-click, and select Block.
  4. Under Application Overrides or Filter Overrides, add targeted block rules for specific protocols (e.g., BitTorrent, TOR) if fine-grained control is required.
  5. Click Apply.

Step 5: Configure the IPS Sensor

Navigate to Security Profiles > Intrusion Prevention.

  1. Click Create New.
  2. Set Name to IPS_Profile_Outbound.
  3. Under IPS Filters, click Add Filter.
  4. Filter by Target: Client and set Severity to High and Critical.
  5. Set the filter action to Block.
  6. Click Apply.

Step 6: Configure SSL/SSH Inspection

Navigate to Security Profiles > SSL/SSH Inspection.

  1. Select an existing deep inspection profile or click Create New. Name it SSL_Deep_Inspection.
  2. Set Inspection Method to Full Inspection (Deep Inspection).
  3. Select the CA Certificate generated by or imported into your FortiGate.
  4. Configure Untrusted SSL Certificates to Block to prevent users from bypassing invalid remote cert warnings.
  5. Save the profile.

Step 7: Apply Profiles to the Firewall Policy

Navigate to Policy & Objects > Firewall Policy.

  1. Select your outbound Internet policy (or click Create New).
  2. Configure standard firewall policy match parameters:
    • Incoming Interface: port2 (LAN)
    • Outgoing Interface: port1 (WAN)
    • Source: LAB_LAN_Subnet
    • Destination: all
    • Service: ALL
    • Action: ACCEPT
    • NAT: Enabled (Use Outgoing Interface Address)
  3. Scroll down to the Security Profiles section.
  4. Toggle Security Profiles to ON.
  5. Select inspection mode (Flow or Proxy) matching your Security Profiles build strategy.
  6. Enable and attach each created profile:
    • AntiVirus: AV_Profile_Outbound
    • Web Filter: WF_Profile_Outbound
    • Application Control: AC_Profile_Outbound
    • IPS: IPS_Profile_Outbound
    • SSL Inspection: SSL_Deep_Inspection
  7. Set Log Allowed Traffic to All Sessions to capture security logs for analysis.
  8. Click OK to save the policy.

Configuring FortiGate Security Profiles via CLI

Below is the complete FortiOS CLI configuration sequence for defining the security profiles and applying them to the outbound firewall policy. This syntax applies directly to modern FortiOS releases.

config antivirus profile
    edit "AV_Profile_Outbound"
        set comment "Outbound Antivirus scanning profile"
        config http
            set options scan
        end
        config ftp
            set options scan
        end
    next
end

config webfilter profile
    edit "WF_Profile_Outbound"
        set comment "Outbound web filtering profile"
        config ftgd-wf
            config filters
                edit 1
                    set category 26
                    set action block
                next
                edit 2
                    set category 61
                    set action block
                next
            end
        end
    next
end

config application list
    edit "AC_Profile_Outbound"
        set comment "Block P2P and proxy applications"
        config entries
            edit 1
                set category 2
                set action block
            next
        end
    next
end

config ips sensor
    edit "IPS_Profile_Outbound"
        set comment "Client protection against high severity threats"
        config entries
            edit 1
                set location client
                set severity high critical
                set action block
            next
        end
    next
end

config firewall policy
    edit 1
        set name "LAN_to_Internet_Outbound"
        set srcintf "port2"
        set dstintf "port1"
        set action accept
        set srcaddr "LAB_LAN_Subnet"
        set dstaddr "all"
        set schedule "always"
        set service "ALL"
        set utm-status enable
        set ssl-ssh-profile "SSL_Deep_Inspection"
        set av-profile "AV_Profile_Outbound"
        set webfilter-profile "WF_Profile_Outbound"
        set application-list "AC_Profile_Outbound"
        set ips-sensor "IPS_Profile_Outbound"
        set nat enable
        set logtraffic all
    next
end

How Traffic Flows Through FortiOS Security Profiles

Understanding packet processing within FortiOS is essential for performance optimization and debugging. FortiGate uses stateful inspection combined with security processors (NP and CP hardware offloading) and protocol inspection engines.

Ingress Packet (port2)
       │
       ▼
Routing Lookup & Policy Match (Policy ID 1)
       │
       ▼
Session Creation & NAT Evaluation
       │
       ▼
Is SSL Inspection Enabled? 
 ├──► Yes ──► SSL/SSH Engine Decrypts Traffic (CP9 Offload if available)
 └──► No  ──► Proceed directly
       │
       ▼
Security Profile Evaluation (UTM Architecture):
 1. IPS & Application Control (IPS Engine - Pattern Matching)
 2. Antivirus Engine (File Scanning & Signature Lookup)
 3. Web Filtering Engine (Category / Rating Lookup & URL Filters)
       │
       ▼
Decision Point:
 ├──► Block Detected? ──► Drop Packet / Send Block Page to User
 └──► Clean Traffic?  ──► Encrypt Traffic (if decrypted) ──► Egress Packet (port1)

When a client initiates a request, FortiOS first evaluates ingress routing and policy match parameters. Once Policy ID 1 is matched, FortiGate evaluates whether Unified Threat Management (UTM) feature inspection is required (set utm-status enable).

If SSL Deep Inspection is configured, the SSL/SSH engine intercepting the stream performs a TLS handshake with both the client and the remote destination. It decrypts the payload into cleartext in memory. The unencrypted payload is then evaluated sequentially by the IPS engine, Application Control parser, Antivirus engine, and Web Filtering engine. If all engines permit the payload, FortiGate re-encrypts the stream using its local certificate and forwards it out the egress WAN interface.

Verification

Verify that security profiles are actively processing sessions using both CLI commands and GUI diagnostic monitoring tools.

1. CLI Session Verification

Check the active session table to confirm security profile engines are attached to traffic flows originating from your test host IP address (e.g., 10.0.1.10):

diagnose firewall session list filter saddr 10.0.1.10

Look for lines indicating active profile enforcement within the output flags, such as helper=auto, utm, or npu info showing offload bypass for security inspection.

2. Verify FortiGuard Connectivity

Confirm the FortiGate can reach FortiGuard servers for live rating lookups and signature updates:

diagnose autoupdate status

Check that the update result fields output Succeeded for AV, IPS, and Web Filtering rating services.

3. Client Testing

  • Antivirus Check: Attempt to download the standard EICAR anti-malware test file via HTTP/HTTPS. FortiGate should intercept the transfer and display an antivirus block page.
  • Web Filtering Check: Navigate to a URL in a blocked category (e.g., http://www.gambling.com or Fortinet’s rating demonstration URL http://urlfortinet.com/testing/html/blocked.html). Confirm the browser displays the FortiGate Web Filter block page.
  • Application Control Check: Launch a blocked P2P client or application on the host machine and confirm connection establishment fails.

Troubleshooting Security Profile Issues

If traffic is unexpectedly dropped or security profiles fail to inspect traffic as expected, use the following structured diagnostic workflow.

Debug Flow Walkthrough

The FortiOS debug flow utility shows policy matching, NAT, and profile processing in real time.

Caution: Running CLI debug commands on production firewalls with high traffic volume can generate significant CPU load and log output. Always filter debugs by a specific source host IP address.
diagnose debug reset
diagnose debug flow filter saddr 10.0.1.10
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable

Observe the live terminal output while attempting traffic from host 10.0.1.10. Ensure you turn off debugging immediately after test completion:

diagnose debug disable
diagnose debug reset

Common Diagnostic Symptoms

Symptom Likely Cause Resolution Steps
Encrypted HTTPS malware downloads or blocked URLs bypass detection completely. Only Certificate Inspection is applied instead of Deep SSL Inspection. Certificate inspection only inspects SNI headers, not HTTP payloads. Switch the SSL profile on the firewall policy to a Deep Inspection profile (SSL_Deep_Inspection) and ensure client systems trust the FortiGate CA.
Users encounter untrusted certificate errors on all HTTPS websites. Clients do not trust the CA certificate configured in the FortiGate Deep SSL Inspection profile. Export the local FortiGate CA certificate and deploy it to client trust stores (Trusted Root Certification Authorities) via Windows Active Directory GPO or MDM.
Web filtering blocks pages slowly or fails open continuously. FortiGate cannot reach FortiGuard servers for DNS/rating resolution. Check DNS settings (config system dns) and verify outbound port UDP 53 / UDP 8888 or HTTPS communication to FortiGuard infrastructure.
Security profiles appear assigned in the GUI but fail to log or inspect sessions. UTM parameter status is disabled at the policy level in CLI. Verify the policy CLI contains set utm-status enable and specific profile assignments are explicitly declared.

Common Mistakes

  1. Expecting Payload Inspection Without Deep SSL Inspection: Over 80% of modern web traffic is encrypted using TLS. Applying Antivirus or Web Filtering keywords to encrypted HTTPS sessions using simple Certificate Inspection will only evaluate basic IP/SNI details. Payload inspection requires full deep inspection.
  2. Uncontrolled CA Certificate Deployment: Enabling Deep Inspection without pre-deploying the FortiGate CA certificate to endpoints results in immediate TLS security warnings in every client browser.
  3. Mixing Inspection Modes Unintentionally: Combining flow-based profiles and proxy-based profiles across multiple policies on low-spec hardware without understanding memory utilization can lead to conserving mode triggers.
  4. Over-allocating Logging Parameters: Setting logtraffic all on extremely high-throughput backup rules or bulk storage policies can exhaust disk/FortiAnalyzer bandwidth rapidly.
  5. Unchecked Security Profile Overlap: Applying strict IPS sensors alongside heavy proxy profiles without tuning signature pools cause elevated CPU performance bottlenecks.

Production Considerations

  • Resource Overhead vs. Inspection Mode: Flow-based processing inspects packet streams as they pass through memory without full protocol buffering, yielding higher throughput and lower latency. Proxy-based inspection buffers full files and payloads before delivering them, offering advanced options (such as payload modification and precise file construction) at the cost of higher memory and CPU utilization. Choose the mode that aligns with your hardware specifications and security baseline.
  • Hardware Acceleration (SPU Offloading): FortiGate models equipped with CP9 or NP7 Security Processing Units offload intensive cryptographic operations (SSL decryption) and pattern matching. Ensure offloading features remain enabled in production unless explicitly troubleshooting packet drops.
  • Enterprise PKI Integration: Instead of using self-signed FortiGate CA certificates for SSL inspection, generate a Certificate Signing Request (CSR) from the FortiGate and sign it using your internal Enterprise Subordinate Certificate Authority. Browsers automatically trust certificates issued by established enterprise PKIs.
  • Exclusion Lists: Sensitive web destinations such as financial institutions, health portals, and strict pin-cert apps (like Zoom or Dropbox) should be added to the SSL inspection bypass list to avoid breaking client connectivity.

Related FortiGate Guides

Summary

Applying FortiGate security profiles to standard firewall policies transforms simple access control rules into an enterprise threat-prevention system. By layering Antivirus, Web Filtering, Application Control, IPS, and SSL Deep Inspection onto outbound traffic flows, FortiGate administrators achieve granular visibility and multi-tiered defense at the perimeter. Always ensure endpoint certificate distribution is completed before enabling Deep SSL inspection in production networks.