Standard Layer 3 and Layer 4 firewall policies filter traffic based strictly on source IP, destination IP, protocol, and port. While this stateful inspection controls basic network access, it cannot protect your internal users against malicious web destinations, drive-by malware downloads, or evasive application-layer threats. Applying FortiGate security profiles to your firewall policies upgrades basic packet filtering into full Layer 7 Next-Generation Firewall (NGFW) threat inspection.
In this technical tutorial, you will learn how to build, tune, and attach FortiGate security profiles—including Antivirus, Web Filtering, Application Control, Intrusion Prevention System (IPS), and SSL Inspection—to outbound firewall policies. We will also examine packet processing flows, verification procedures, and step-by-step troubleshooting workflows.
Real-Life Scenario
Acme Corporation needs to secure Internet access for its office workers on the internal network. The enterprise permits outbound web traffic, but corporate compliance demands multi-layered security controls:
- Antivirus: Block malicious payload downloads over HTTP, HTTPS, and FTP.
- Web Filtering: Block access to known phishing, malware distribution, adult, and high-risk domain categories. Enforce safe searching.
- Application Control: Block high-risk applications, peer-to-peer (P2P) file sharing, and anonymizing proxies, regardless of port numbers used.
- Intrusion Prevention (IPS): Block client-side exploits and command-and-control (C2) botnet traffic.
- SSL Inspection: Decrypt outbound HTTPS sessions so the inspection engines can examine encrypted payloads.
Lab Topology
The following diagram shows the lab network topology used in this configuration guide.
[ Internal Hosts ]
(10.0.1.0/24)
|
[ port2: 10.0.1.1 ] (LAN Interface)
+------------------------------------------------+
| FortiGate Firewall (FortiOS) |
| |
| Security Profiles Applied: |
| - Antivirus Profile |
| - Web Filter Profile |
| - Application Control Profile |
| - IPS Sensor |
| - SSL/SSH Inspection Profile |
+------------------------------------------------+
[ port1: 198.51.100.2/24 ] (WAN Interface)
|
[ Next-Hop ISP Router: 198.51.100.1 ]
|
( Internet )
Example Addressing and Objects
The table below details the interfaces, network address objects, and security profile names used throughout this guide. All IP addresses represent example/lab assignments.
| Object / Item Name | Type | Example Value | Purpose |
|---|---|---|---|
port1 |
Physical Interface | 198.51.100.2/24 (GW: 198.51.100.1) |
WAN egress interface connecting to ISP (EXAMPLE) |
port2 |
Physical Interface | 10.0.1.1/24 |
LAN ingress interface connecting to internal hosts (EXAMPLE) |
LAB_LAN_Subnet |
Address Object | 10.0.1.0/24 |
Subnet object representing internal corporate users |
AV_Profile_Outbound |
Antivirus Profile | Flow-based AV Engine | Inspects downloads for viruses and ransomware signatures |
WF_Profile_Outbound |
Web Filter Profile | Category Blocking & URL Filter | Restricts access to malicious and inappropriate web content |
AC_Profile_Outbound |
Application Control Profile | App Signatures & Categories | Blocks P2P, tunnelers, and unapproved web services |
IPS_Profile_Outbound |
IPS Sensor | Client Security Signatures | Detects and blocks client-side exploits and C2 callouts |
SSL_Deep_Inspection |
SSL/SSH Profile | Deep Inspection (Custom CA) | Decrypts encrypted SSL/TLS traffic for inspection engines |
Prerequisites
- Active Subscriptions: Active FortiGuard security subscriptions for Antivirus, Web Filtering, Application Control, and IPS.
- Routing and Connectivity: Pre-existing layer 3 routing and IP connectivity between the LAN and WAN.
- CA Certificate Installation: If using Deep SSL Inspection, the FortiGate CA certificate (or an enterprise Subordinate CA signed by your internal PKI) must be deployed to client browsers and trust stores via GPO, MDM, or manual installation.
- FortiOS Version Context: Note that exact GUI menu locations and CLI parameters may vary slightly depending on your FortiOS release (such as 7.0, 7.2, or 7.4) and platform feature visibility settings.
Step-by-Step GUI Configuration
Step 1: Verify FortiGuard Entitlements
Navigate to System > FortiGuard in the FortiGate GUI. Confirm that the status for AntiVirus, Web Filter, Application Control, and Intrusion Prevention displays an active license indicator. If signatures are outdated, click Update Antivirus Definitions and Update Engine & IPS Definitions.
Step 2: Configure the Antivirus Profile
Navigate to Security Profiles > Antivirus.
- Click Create New.
- Set Name to
AV_Profile_Outbound. - Select Flow-based or Proxy-based inspection mode depending on your system strategy (Flow mode offers higher throughput; Proxy mode offers complete payload buffering).
- Enable scanning for HTTP, FTP, SFTP, and email protocols as required.
- Enable FortiSandbox Inspection if an integrated FortiSandbox appliance or cloud service is available.
- Click Apply.
Step 3: Configure the Web Filter Profile
Navigate to Security Profiles > Web Filter.
- Click Create New.
- Set Name to
WF_Profile_Outbound. - Under FortiGuard Category Based Filter, enable the feature.
- Expand categories and set sensitive or dangerous groups (e.g., Potentially Liable, Security Risk, Adult Material) to Block.
- Under Static URL Filter, enable URL Filter options if specific explicit site blocks or overrides are required.
- Enable Search Engines > Enforce SafeSearch on supported search providers if required.
- Click Apply.
Step 4: Configure the Application Control Profile
Navigate to Security Profiles > Application Control.
- Click Create New.
- Set Name to
AC_Profile_Outbound. - In the Categories table, locate high-risk application groups such as P2P and Proxy, right-click, and select Block.
- Under Application Overrides or Filter Overrides, add targeted block rules for specific protocols (e.g., BitTorrent, TOR) if fine-grained control is required.
- Click Apply.
Step 5: Configure the IPS Sensor
Navigate to Security Profiles > Intrusion Prevention.
- Click Create New.
- Set Name to
IPS_Profile_Outbound. - Under IPS Filters, click Add Filter.
- Filter by Target: Client and set Severity to High and Critical.
- Set the filter action to Block.
- Click Apply.
Step 6: Configure SSL/SSH Inspection
Navigate to Security Profiles > SSL/SSH Inspection.
- Select an existing deep inspection profile or click Create New. Name it
SSL_Deep_Inspection. - Set Inspection Method to Full Inspection (Deep Inspection).
- Select the CA Certificate generated by or imported into your FortiGate.
- Configure Untrusted SSL Certificates to Block to prevent users from bypassing invalid remote cert warnings.
- Save the profile.
Step 7: Apply Profiles to the Firewall Policy
Navigate to Policy & Objects > Firewall Policy.
- Select your outbound Internet policy (or click Create New).
- Configure standard firewall policy match parameters:
- Incoming Interface:
port2(LAN) - Outgoing Interface:
port1(WAN) - Source:
LAB_LAN_Subnet - Destination:
all - Service:
ALL - Action:
ACCEPT - NAT: Enabled (Use Outgoing Interface Address)
- Incoming Interface:
- Scroll down to the Security Profiles section.
- Toggle Security Profiles to ON.
- Select inspection mode (Flow or Proxy) matching your Security Profiles build strategy.
- Enable and attach each created profile:
- AntiVirus:
AV_Profile_Outbound - Web Filter:
WF_Profile_Outbound - Application Control:
AC_Profile_Outbound - IPS:
IPS_Profile_Outbound - SSL Inspection:
SSL_Deep_Inspection
- AntiVirus:
- Set Log Allowed Traffic to All Sessions to capture security logs for analysis.
- Click OK to save the policy.
Configuring FortiGate Security Profiles via CLI
Below is the complete FortiOS CLI configuration sequence for defining the security profiles and applying them to the outbound firewall policy. This syntax applies directly to modern FortiOS releases.
config antivirus profile
edit "AV_Profile_Outbound"
set comment "Outbound Antivirus scanning profile"
config http
set options scan
end
config ftp
set options scan
end
next
end
config webfilter profile
edit "WF_Profile_Outbound"
set comment "Outbound web filtering profile"
config ftgd-wf
config filters
edit 1
set category 26
set action block
next
edit 2
set category 61
set action block
next
end
end
next
end
config application list
edit "AC_Profile_Outbound"
set comment "Block P2P and proxy applications"
config entries
edit 1
set category 2
set action block
next
end
next
end
config ips sensor
edit "IPS_Profile_Outbound"
set comment "Client protection against high severity threats"
config entries
edit 1
set location client
set severity high critical
set action block
next
end
next
end
config firewall policy
edit 1
set name "LAN_to_Internet_Outbound"
set srcintf "port2"
set dstintf "port1"
set action accept
set srcaddr "LAB_LAN_Subnet"
set dstaddr "all"
set schedule "always"
set service "ALL"
set utm-status enable
set ssl-ssh-profile "SSL_Deep_Inspection"
set av-profile "AV_Profile_Outbound"
set webfilter-profile "WF_Profile_Outbound"
set application-list "AC_Profile_Outbound"
set ips-sensor "IPS_Profile_Outbound"
set nat enable
set logtraffic all
next
end
How Traffic Flows Through FortiOS Security Profiles
Understanding packet processing within FortiOS is essential for performance optimization and debugging. FortiGate uses stateful inspection combined with security processors (NP and CP hardware offloading) and protocol inspection engines.
Ingress Packet (port2)
│
▼
Routing Lookup & Policy Match (Policy ID 1)
│
▼
Session Creation & NAT Evaluation
│
▼
Is SSL Inspection Enabled?
├──► Yes ──► SSL/SSH Engine Decrypts Traffic (CP9 Offload if available)
└──► No ──► Proceed directly
│
▼
Security Profile Evaluation (UTM Architecture):
1. IPS & Application Control (IPS Engine - Pattern Matching)
2. Antivirus Engine (File Scanning & Signature Lookup)
3. Web Filtering Engine (Category / Rating Lookup & URL Filters)
│
▼
Decision Point:
├──► Block Detected? ──► Drop Packet / Send Block Page to User
└──► Clean Traffic? ──► Encrypt Traffic (if decrypted) ──► Egress Packet (port1)
When a client initiates a request, FortiOS first evaluates ingress routing and policy match parameters. Once Policy ID 1 is matched, FortiGate evaluates whether Unified Threat Management (UTM) feature inspection is required (set utm-status enable).
If SSL Deep Inspection is configured, the SSL/SSH engine intercepting the stream performs a TLS handshake with both the client and the remote destination. It decrypts the payload into cleartext in memory. The unencrypted payload is then evaluated sequentially by the IPS engine, Application Control parser, Antivirus engine, and Web Filtering engine. If all engines permit the payload, FortiGate re-encrypts the stream using its local certificate and forwards it out the egress WAN interface.
Verification
Verify that security profiles are actively processing sessions using both CLI commands and GUI diagnostic monitoring tools.
1. CLI Session Verification
Check the active session table to confirm security profile engines are attached to traffic flows originating from your test host IP address (e.g., 10.0.1.10):
diagnose firewall session list filter saddr 10.0.1.10
Look for lines indicating active profile enforcement within the output flags, such as helper=auto, utm, or npu info showing offload bypass for security inspection.
2. Verify FortiGuard Connectivity
Confirm the FortiGate can reach FortiGuard servers for live rating lookups and signature updates:
diagnose autoupdate status
Check that the update result fields output Succeeded for AV, IPS, and Web Filtering rating services.
3. Client Testing
- Antivirus Check: Attempt to download the standard EICAR anti-malware test file via HTTP/HTTPS. FortiGate should intercept the transfer and display an antivirus block page.
- Web Filtering Check: Navigate to a URL in a blocked category (e.g.,
http://www.gambling.comor Fortinet’s rating demonstration URLhttp://urlfortinet.com/testing/html/blocked.html). Confirm the browser displays the FortiGate Web Filter block page. - Application Control Check: Launch a blocked P2P client or application on the host machine and confirm connection establishment fails.
Troubleshooting Security Profile Issues
If traffic is unexpectedly dropped or security profiles fail to inspect traffic as expected, use the following structured diagnostic workflow.
Debug Flow Walkthrough
The FortiOS debug flow utility shows policy matching, NAT, and profile processing in real time.
diagnose debug reset
diagnose debug flow filter saddr 10.0.1.10
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable
Observe the live terminal output while attempting traffic from host 10.0.1.10. Ensure you turn off debugging immediately after test completion:
diagnose debug disable
diagnose debug reset
Common Diagnostic Symptoms
| Symptom | Likely Cause | Resolution Steps |
|---|---|---|
| Encrypted HTTPS malware downloads or blocked URLs bypass detection completely. | Only Certificate Inspection is applied instead of Deep SSL Inspection. Certificate inspection only inspects SNI headers, not HTTP payloads. | Switch the SSL profile on the firewall policy to a Deep Inspection profile (SSL_Deep_Inspection) and ensure client systems trust the FortiGate CA. |
| Users encounter untrusted certificate errors on all HTTPS websites. | Clients do not trust the CA certificate configured in the FortiGate Deep SSL Inspection profile. | Export the local FortiGate CA certificate and deploy it to client trust stores (Trusted Root Certification Authorities) via Windows Active Directory GPO or MDM. |
| Web filtering blocks pages slowly or fails open continuously. | FortiGate cannot reach FortiGuard servers for DNS/rating resolution. | Check DNS settings (config system dns) and verify outbound port UDP 53 / UDP 8888 or HTTPS communication to FortiGuard infrastructure. |
| Security profiles appear assigned in the GUI but fail to log or inspect sessions. | UTM parameter status is disabled at the policy level in CLI. | Verify the policy CLI contains set utm-status enable and specific profile assignments are explicitly declared. |
Common Mistakes
- Expecting Payload Inspection Without Deep SSL Inspection: Over 80% of modern web traffic is encrypted using TLS. Applying Antivirus or Web Filtering keywords to encrypted HTTPS sessions using simple Certificate Inspection will only evaluate basic IP/SNI details. Payload inspection requires full deep inspection.
- Uncontrolled CA Certificate Deployment: Enabling Deep Inspection without pre-deploying the FortiGate CA certificate to endpoints results in immediate TLS security warnings in every client browser.
- Mixing Inspection Modes Unintentionally: Combining flow-based profiles and proxy-based profiles across multiple policies on low-spec hardware without understanding memory utilization can lead to conserving mode triggers.
- Over-allocating Logging Parameters: Setting
logtraffic allon extremely high-throughput backup rules or bulk storage policies can exhaust disk/FortiAnalyzer bandwidth rapidly. - Unchecked Security Profile Overlap: Applying strict IPS sensors alongside heavy proxy profiles without tuning signature pools cause elevated CPU performance bottlenecks.
Production Considerations
- Resource Overhead vs. Inspection Mode: Flow-based processing inspects packet streams as they pass through memory without full protocol buffering, yielding higher throughput and lower latency. Proxy-based inspection buffers full files and payloads before delivering them, offering advanced options (such as payload modification and precise file construction) at the cost of higher memory and CPU utilization. Choose the mode that aligns with your hardware specifications and security baseline.
- Hardware Acceleration (SPU Offloading): FortiGate models equipped with CP9 or NP7 Security Processing Units offload intensive cryptographic operations (SSL decryption) and pattern matching. Ensure offloading features remain enabled in production unless explicitly troubleshooting packet drops.
- Enterprise PKI Integration: Instead of using self-signed FortiGate CA certificates for SSL inspection, generate a Certificate Signing Request (CSR) from the FortiGate and sign it using your internal Enterprise Subordinate Certificate Authority. Browsers automatically trust certificates issued by established enterprise PKIs.
- Exclusion Lists: Sensitive web destinations such as financial institutions, health portals, and strict pin-cert apps (like Zoom or Dropbox) should be added to the SSL inspection bypass list to avoid breaking client connectivity.
Related FortiGate Guides
- FortiGate web filtering
- FortiGate SSL deep inspection
- FortiGate session troubleshooting
- FortiGate SD-WAN configuration
Summary
Applying FortiGate security profiles to standard firewall policies transforms simple access control rules into an enterprise threat-prevention system. By layering Antivirus, Web Filtering, Application Control, IPS, and SSL Deep Inspection onto outbound traffic flows, FortiGate administrators achieve granular visibility and multi-tiered defense at the perimeter. Always ensure endpoint certificate distribution is completed before enabling Deep SSL inspection in production networks.