{"id":541,"date":"2026-08-16T11:11:03","date_gmt":"2026-08-16T05:41:03","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/apply-fortigate-security-profiles-to-firewall-policies\/"},"modified":"2026-09-14T04:33:11","modified_gmt":"2026-09-13T23:03:11","slug":"apply-fortigate-security-profiles-to-firewall-policies","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/","title":{"rendered":"How to Apply FortiGate Security Profiles to Firewall Policies"},"content":{"rendered":"<p>Standard Layer 3 and Layer 4 firewall policies filter traffic based strictly on source IP, destination IP, protocol, and port. While this stateful inspection controls basic network access, it cannot protect your internal users against malicious web destinations, drive-by malware downloads, or evasive application-layer threats. Applying <strong>FortiGate security profiles<\/strong> to your firewall policies upgrades basic packet filtering into full Layer 7 Next-Generation Firewall (NGFW) threat inspection.<\/p>\n<p>In this technical tutorial, you will learn how to build, tune, and attach FortiGate security profiles\u2014including Antivirus, Web Filtering, Application Control, Intrusion Prevention System (IPS), and SSL Inspection\u2014to outbound firewall policies. We will also examine packet processing flows, verification procedures, and step-by-step troubleshooting workflows.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>Acme Corporation needs to secure Internet access for its office workers on the internal network. The enterprise permits outbound web traffic, but corporate compliance demands multi-layered security controls:<\/p>\n<ul>\n<li><strong>Antivirus:<\/strong> Block malicious payload downloads over HTTP, HTTPS, and FTP.<\/li>\n<li><strong>Web Filtering:<\/strong> Block access to known phishing, malware distribution, adult, and high-risk domain categories. Enforce safe searching.<\/li>\n<li><strong>Application Control:<\/strong> Block high-risk applications, peer-to-peer (P2P) file sharing, and anonymizing proxies, regardless of port numbers used.<\/li>\n<li><strong>Intrusion Prevention (IPS):<\/strong> Block client-side exploits and command-and-control (C2) botnet traffic.<\/li>\n<li><strong>SSL Inspection:<\/strong> Decrypt outbound HTTPS sessions so the inspection engines can examine encrypted payloads.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The following diagram shows the lab network topology used in this configuration guide.<\/p>\n<pre>\n [ Internal Hosts ]\n  (10.0.1.0\/24)\n        |\n [ port2: 10.0.1.1 ] (LAN Interface)\n+------------------------------------------------+\n|         FortiGate Firewall (FortiOS)           |\n|                                                |\n| Security Profiles Applied:                     |\n|  - Antivirus Profile                           |\n|  - Web Filter Profile                          |\n|  - Application Control Profile                 |\n|  - IPS Sensor                                  |\n|  - SSL\/SSH Inspection Profile                  |\n+------------------------------------------------+\n [ port1: 198.51.100.2\/24 ] (WAN Interface)\n        |\n [ Next-Hop ISP Router: 198.51.100.1 ]\n        |\n   ( Internet )\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The table below details the interfaces, network address objects, and security profile names used throughout this guide. All IP addresses represent example\/lab assignments.<\/p>\n<table>\n<thead>\n<tr>\n<th>Object \/ Item Name<\/th>\n<th>Type<\/th>\n<th>Example Value<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>port1<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>198.51.100.2\/24<\/code> (GW: 198.51.100.1)<\/td>\n<td>WAN egress interface connecting to ISP (EXAMPLE)<\/td>\n<\/tr>\n<tr>\n<td><code>port2<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>10.0.1.1\/24<\/code><\/td>\n<td>LAN ingress interface connecting to internal hosts (EXAMPLE)<\/td>\n<\/tr>\n<tr>\n<td><code>LAB_LAN_Subnet<\/code><\/td>\n<td>Address Object<\/td>\n<td><code>10.0.1.0\/24<\/code><\/td>\n<td>Subnet object representing internal corporate users<\/td>\n<\/tr>\n<tr>\n<td><code>AV_Profile_Outbound<\/code><\/td>\n<td>Antivirus Profile<\/td>\n<td>Flow-based AV Engine<\/td>\n<td>Inspects downloads for viruses and ransomware signatures<\/td>\n<\/tr>\n<tr>\n<td><code>WF_Profile_Outbound<\/code><\/td>\n<td>Web Filter Profile<\/td>\n<td>Category Blocking &amp; URL Filter<\/td>\n<td>Restricts access to malicious and inappropriate web content<\/td>\n<\/tr>\n<tr>\n<td><code>AC_Profile_Outbound<\/code><\/td>\n<td>Application Control Profile<\/td>\n<td>App Signatures &amp; Categories<\/td>\n<td>Blocks P2P, tunnelers, and unapproved web services<\/td>\n<\/tr>\n<tr>\n<td><code>IPS_Profile_Outbound<\/code><\/td>\n<td>IPS Sensor<\/td>\n<td>Client Security Signatures<\/td>\n<td>Detects and blocks client-side exploits and C2 callouts<\/td>\n<\/tr>\n<tr>\n<td><code>SSL_Deep_Inspection<\/code><\/td>\n<td>SSL\/SSH Profile<\/td>\n<td>Deep Inspection (Custom CA)<\/td>\n<td>Decrypts encrypted SSL\/TLS traffic for inspection engines<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<ul>\n<li><strong>Active Subscriptions:<\/strong> Active FortiGuard security subscriptions for Antivirus, Web Filtering, Application Control, and IPS.<\/li>\n<li><strong>Routing and Connectivity:<\/strong> Pre-existing layer 3 routing and IP connectivity between the LAN and WAN.<\/li>\n<li><strong>CA Certificate Installation:<\/strong> If using Deep SSL Inspection, the FortiGate CA certificate (or an enterprise Subordinate CA signed by your internal PKI) must be deployed to client browsers and trust stores via GPO, MDM, or manual installation.<\/li>\n<li><strong>FortiOS Version Context:<\/strong> Note that exact GUI menu locations and CLI parameters may vary slightly depending on your FortiOS release (such as 7.0, 7.2, or 7.4) and platform feature visibility settings.<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<h3>Step 1: Verify FortiGuard Entitlements<\/h3>\n<p>Navigate to <strong>System &gt; FortiGuard<\/strong> in the FortiGate GUI. Confirm that the status for <strong>AntiVirus<\/strong>, <strong>Web Filter<\/strong>, <strong>Application Control<\/strong>, and <strong>Intrusion Prevention<\/strong> displays an active license indicator. If signatures are outdated, click <strong>Update Antivirus Definitions<\/strong> and <strong>Update Engine &amp; IPS Definitions<\/strong>.<\/p>\n<h3>Step 2: Configure the Antivirus Profile<\/h3>\n<p>Navigate to <strong>Security Profiles &gt; Antivirus<\/strong>.<\/p>\n<ol>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Set <strong>Name<\/strong> to <code>AV_Profile_Outbound<\/code>.<\/li>\n<li>Select <strong>Flow-based<\/strong> or <strong>Proxy-based<\/strong> inspection mode depending on your system strategy (Flow mode offers higher throughput; Proxy mode offers complete payload buffering).<\/li>\n<li>Enable scanning for <strong>HTTP<\/strong>, <strong>FTP<\/strong>, <strong>SFTP<\/strong>, and email protocols as required.<\/li>\n<li>Enable <strong>FortiSandbox Inspection<\/strong> if an integrated FortiSandbox appliance or cloud service is available.<\/li>\n<li>Click <strong>Apply<\/strong>.<\/li>\n<\/ol>\n<h3>Step 3: Configure the Web Filter Profile<\/h3>\n<p>Navigate to <strong>Security Profiles &gt; Web Filter<\/strong>.<\/p>\n<ol>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Set <strong>Name<\/strong> to <code>WF_Profile_Outbound<\/code>.<\/li>\n<li>Under <strong>FortiGuard Category Based Filter<\/strong>, enable the feature.<\/li>\n<li>Expand categories and set sensitive or dangerous groups (e.g., <em>Potentially Liable<\/em>, <em>Security Risk<\/em>, <em>Adult Material<\/em>) to <strong>Block<\/strong>.<\/li>\n<li>Under <strong>Static URL Filter<\/strong>, enable URL Filter options if specific explicit site blocks or overrides are required.<\/li>\n<li>Enable <strong>Search Engines &gt; Enforce SafeSearch<\/strong> on supported search providers if required.<\/li>\n<li>Click <strong>Apply<\/strong>.<\/li>\n<\/ol>\n<h3>Step 4: Configure the Application Control Profile<\/h3>\n<p>Navigate to <strong>Security Profiles &gt; Application Control<\/strong>.<\/p>\n<ol>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Set <strong>Name<\/strong> to <code>AC_Profile_Outbound<\/code>.<\/li>\n<li>In the <strong>Categories<\/strong> table, locate high-risk application groups such as <strong>P2P<\/strong> and <strong>Proxy<\/strong>, right-click, and select <strong>Block<\/strong>.<\/li>\n<li>Under <strong>Application Overrides<\/strong> or <strong>Filter Overrides<\/strong>, add targeted block rules for specific protocols (e.g., BitTorrent, TOR) if fine-grained control is required.<\/li>\n<li>Click <strong>Apply<\/strong>.<\/li>\n<\/ol>\n<h3>Step 5: Configure the IPS Sensor<\/h3>\n<p>Navigate to <strong>Security Profiles &gt; Intrusion Prevention<\/strong>.<\/p>\n<ol>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Set <strong>Name<\/strong> to <code>IPS_Profile_Outbound<\/code>.<\/li>\n<li>Under <strong>IPS Filters<\/strong>, click <strong>Add Filter<\/strong>.<\/li>\n<li>Filter by <strong>Target: Client<\/strong> and set <strong>Severity<\/strong> to <em>High<\/em> and <em>Critical<\/em>.<\/li>\n<li>Set the filter action to <strong>Block<\/strong>.<\/li>\n<li>Click <strong>Apply<\/strong>.<\/li>\n<\/ol>\n<h3>Step 6: Configure SSL\/SSH Inspection<\/h3>\n<p>Navigate to <strong>Security Profiles &gt; SSL\/SSH Inspection<\/strong>.<\/p>\n<ol>\n<li>Select an existing deep inspection profile or click <strong>Create New<\/strong>. Name it <code>SSL_Deep_Inspection<\/code>.<\/li>\n<li>Set <strong>Inspection Method<\/strong> to <strong>Full Inspection<\/strong> (Deep Inspection).<\/li>\n<li>Select the <strong>CA Certificate<\/strong> generated by or imported into your FortiGate.<\/li>\n<li>Configure <strong>Untrusted SSL Certificates<\/strong> to <strong>Block<\/strong> to prevent users from bypassing invalid remote cert warnings.<\/li>\n<li>Save the profile.<\/li>\n<\/ol>\n<h3>Step 7: Apply Profiles to the Firewall Policy<\/h3>\n<p>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong>.<\/p>\n<ol>\n<li>Select your outbound Internet policy (or click <strong>Create New<\/strong>).<\/li>\n<li>Configure standard firewall policy match parameters:\n<ul>\n<li><strong>Incoming Interface:<\/strong> <code>port2<\/code> (LAN)<\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>port1<\/code> (WAN)<\/li>\n<li><strong>Source:<\/strong> <code>LAB_LAN_Subnet<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>all<\/code><\/li>\n<li><strong>Service:<\/strong> <code>ALL<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<li><strong>NAT:<\/strong> Enabled (Use Outgoing Interface Address)<\/li>\n<\/ul>\n<\/li>\n<li>Scroll down to the <strong>Security Profiles<\/strong> section.<\/li>\n<li>Toggle <strong>Security Profiles<\/strong> to <strong>ON<\/strong>.<\/li>\n<li>Select inspection mode (Flow or Proxy) matching your Security Profiles build strategy.<\/li>\n<li>Enable and attach each created profile:\n<ul>\n<li><strong>AntiVirus:<\/strong> <code>AV_Profile_Outbound<\/code><\/li>\n<li><strong>Web Filter:<\/strong> <code>WF_Profile_Outbound<\/code><\/li>\n<li><strong>Application Control:<\/strong> <code>AC_Profile_Outbound<\/code><\/li>\n<li><strong>IPS:<\/strong> <code>IPS_Profile_Outbound<\/code><\/li>\n<li><strong>SSL Inspection:<\/strong> <code>SSL_Deep_Inspection<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Set <strong>Log Allowed Traffic<\/strong> to <strong>All Sessions<\/strong> to capture security logs for analysis.<\/li>\n<li>Click <strong>OK<\/strong> to save the policy.<\/li>\n<\/ol>\n<h2>Configuring FortiGate Security Profiles via CLI<\/h2>\n<p>Below is the complete FortiOS CLI configuration sequence for defining the security profiles and applying them to the outbound firewall policy. This syntax applies directly to modern FortiOS releases.<\/p>\n<pre><code>config antivirus profile\n    edit \"AV_Profile_Outbound\"\n        set comment \"Outbound Antivirus scanning profile\"\n        config http\n            set options scan\n        end\n        config ftp\n            set options scan\n        end\n    next\nend\n\nconfig webfilter profile\n    edit \"WF_Profile_Outbound\"\n        set comment \"Outbound web filtering profile\"\n        config ftgd-wf\n            config filters\n                edit 1\n                    set category 26\n                    set action block\n                next\n                edit 2\n                    set category 61\n                    set action block\n                next\n            end\n        end\n    next\nend\n\nconfig application list\n    edit \"AC_Profile_Outbound\"\n        set comment \"Block P2P and proxy applications\"\n        config entries\n            edit 1\n                set category 2\n                set action block\n            next\n        end\n    next\nend\n\nconfig ips sensor\n    edit \"IPS_Profile_Outbound\"\n        set comment \"Client protection against high severity threats\"\n        config entries\n            edit 1\n                set location client\n                set severity high critical\n                set action block\n            next\n        end\n    next\nend\n\nconfig firewall policy\n    edit 1\n        set name \"LAN_to_Internet_Outbound\"\n        set srcintf \"port2\"\n        set dstintf \"port1\"\n        set action accept\n        set srcaddr \"LAB_LAN_Subnet\"\n        set dstaddr \"all\"\n        set schedule \"always\"\n        set service \"ALL\"\n        set utm-status enable\n        set ssl-ssh-profile \"SSL_Deep_Inspection\"\n        set av-profile \"AV_Profile_Outbound\"\n        set webfilter-profile \"WF_Profile_Outbound\"\n        set application-list \"AC_Profile_Outbound\"\n        set ips-sensor \"IPS_Profile_Outbound\"\n        set nat enable\n        set logtraffic all\n    next\nend\n<\/code><\/pre>\n<h2>How Traffic Flows Through FortiOS Security Profiles<\/h2>\n<p>Understanding packet processing within FortiOS is essential for performance optimization and debugging. FortiGate uses stateful inspection combined with security processors (NP and CP hardware offloading) and protocol inspection engines.<\/p>\n<pre>\nIngress Packet (port2)\n       \u2502\n       \u25bc\nRouting Lookup &amp; Policy Match (Policy ID 1)\n       \u2502\n       \u25bc\nSession Creation &amp; NAT Evaluation\n       \u2502\n       \u25bc\nIs SSL Inspection Enabled? \n \u251c\u2500\u2500\u25ba Yes \u2500\u2500\u25ba SSL\/SSH Engine Decrypts Traffic (CP9 Offload if available)\n \u2514\u2500\u2500\u25ba No  \u2500\u2500\u25ba Proceed directly\n       \u2502\n       \u25bc\nSecurity Profile Evaluation (UTM Architecture):\n 1. IPS &amp; Application Control (IPS Engine - Pattern Matching)\n 2. Antivirus Engine (File Scanning &amp; Signature Lookup)\n 3. Web Filtering Engine (Category \/ Rating Lookup &amp; URL Filters)\n       \u2502\n       \u25bc\nDecision Point:\n \u251c\u2500\u2500\u25ba Block Detected? \u2500\u2500\u25ba Drop Packet \/ Send Block Page to User\n \u2514\u2500\u2500\u25ba Clean Traffic?  \u2500\u2500\u25ba Encrypt Traffic (if decrypted) \u2500\u2500\u25ba Egress Packet (port1)\n<\/pre>\n<p>When a client initiates a request, FortiOS first evaluates ingress routing and policy match parameters. Once Policy ID 1 is matched, FortiGate evaluates whether Unified Threat Management (UTM) feature inspection is required (<code>set utm-status enable<\/code>).<\/p>\n<p>If SSL Deep Inspection is configured, the SSL\/SSH engine intercepting the stream performs a TLS handshake with both the client and the remote destination. It decrypts the payload into cleartext in memory. The unencrypted payload is then evaluated sequentially by the IPS engine, Application Control parser, Antivirus engine, and Web Filtering engine. If all engines permit the payload, FortiGate re-encrypts the stream using its local certificate and forwards it out the egress WAN interface.<\/p>\n<h2>Verification<\/h2>\n<p>Verify that security profiles are actively processing sessions using both CLI commands and GUI diagnostic monitoring tools.<\/p>\n<h3>1. CLI Session Verification<\/h3>\n<p>Check the active session table to confirm security profile engines are attached to traffic flows originating from your test host IP address (e.g., <code>10.0.1.10<\/code>):<\/p>\n<pre><code>diagnose firewall session list filter saddr 10.0.1.10\n<\/code><\/pre>\n<p>Look for lines indicating active profile enforcement within the output flags, such as <code>helper=auto<\/code>, <code>utm<\/code>, or <code>npu info<\/code> showing offload bypass for security inspection.<\/p>\n<h3>2. Verify FortiGuard Connectivity<\/h3>\n<p>Confirm the FortiGate can reach FortiGuard servers for live rating lookups and signature updates:<\/p>\n<pre><code>diagnose autoupdate status\n<\/code><\/pre>\n<p>Check that the update result fields output <code>Succeeded<\/code> for AV, IPS, and Web Filtering rating services.<\/p>\n<h3>3. Client Testing<\/h3>\n<ul>\n<li><strong>Antivirus Check:<\/strong> Attempt to download the standard EICAR anti-malware test file via HTTP\/HTTPS. FortiGate should intercept the transfer and display an antivirus block page.<\/li>\n<li><strong>Web Filtering Check:<\/strong> Navigate to a URL in a blocked category (e.g., <code>http:\/\/www.gambling.com<\/code> or Fortinet&#8217;s rating demonstration URL <code>http:\/\/urlfortinet.com\/testing\/html\/blocked.html<\/code>). Confirm the browser displays the FortiGate Web Filter block page.<\/li>\n<li><strong>Application Control Check:<\/strong> Launch a blocked P2P client or application on the host machine and confirm connection establishment fails.<\/li>\n<\/ul>\n<h2>Troubleshooting Security Profile Issues<\/h2>\n<p>If traffic is unexpectedly dropped or security profiles fail to inspect traffic as expected, use the following structured diagnostic workflow.<\/p>\n<h3>Debug Flow Walkthrough<\/h3>\n<p>The FortiOS debug flow utility shows policy matching, NAT, and profile processing in real time.<\/p>\n<div class=\"caution\">\n<strong>Caution:<\/strong> Running CLI debug commands on production firewalls with high traffic volume can generate significant CPU load and log output. Always filter debugs by a specific source host IP address.\n<\/div>\n<pre><code>diagnose debug reset\ndiagnose debug flow filter saddr 10.0.1.10\ndiagnose debug flow show function-name enable\ndiagnose debug flow trace start 100\ndiagnose debug enable\n<\/code><\/pre>\n<p>Observe the live terminal output while attempting traffic from host <code>10.0.1.10<\/code>. Ensure you turn off debugging immediately after test completion:<\/p>\n<pre><code>diagnose debug disable\ndiagnose debug reset\n<\/code><\/pre>\n<h3>Common Diagnostic Symptoms<\/h3>\n<table>\n<thead>\n<tr>\n<th>Symptom<\/th>\n<th>Likely Cause<\/th>\n<th>Resolution Steps<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Encrypted HTTPS malware downloads or blocked URLs bypass detection completely.<\/td>\n<td>Only Certificate Inspection is applied instead of Deep SSL Inspection. Certificate inspection only inspects SNI headers, not HTTP payloads.<\/td>\n<td>Switch the SSL profile on the firewall policy to a Deep Inspection profile (<code>SSL_Deep_Inspection<\/code>) and ensure client systems trust the FortiGate CA.<\/td>\n<\/tr>\n<tr>\n<td>Users encounter untrusted certificate errors on all HTTPS websites.<\/td>\n<td>Clients do not trust the CA certificate configured in the FortiGate Deep SSL Inspection profile.<\/td>\n<td>Export the local FortiGate CA certificate and deploy it to client trust stores (Trusted Root Certification Authorities) via Windows Active Directory GPO or MDM.<\/td>\n<\/tr>\n<tr>\n<td>Web filtering blocks pages slowly or fails open continuously.<\/td>\n<td>FortiGate cannot reach FortiGuard servers for DNS\/rating resolution.<\/td>\n<td>Check DNS settings (<code>config system dns<\/code>) and verify outbound port UDP 53 \/ UDP 8888 or HTTPS communication to FortiGuard infrastructure.<\/td>\n<\/tr>\n<tr>\n<td>Security profiles appear assigned in the GUI but fail to log or inspect sessions.<\/td>\n<td>UTM parameter status is disabled at the policy level in CLI.<\/td>\n<td>Verify the policy CLI contains <code>set utm-status enable<\/code> and specific profile assignments are explicitly declared.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Common Mistakes<\/h2>\n<ol>\n<li><strong>Expecting Payload Inspection Without Deep SSL Inspection:<\/strong> Over 80% of modern web traffic is encrypted using TLS. Applying Antivirus or Web Filtering keywords to encrypted HTTPS sessions using simple Certificate Inspection will only evaluate basic IP\/SNI details. Payload inspection requires full deep inspection.<\/li>\n<li><strong>Uncontrolled CA Certificate Deployment:<\/strong> Enabling Deep Inspection without pre-deploying the FortiGate CA certificate to endpoints results in immediate TLS security warnings in every client browser.<\/li>\n<li><strong>Mixing Inspection Modes Unintentionally:<\/strong> Combining flow-based profiles and proxy-based profiles across multiple policies on low-spec hardware without understanding memory utilization can lead to conserving mode triggers.<\/li>\n<li><strong>Over-allocating Logging Parameters:<\/strong> Setting <code>logtraffic all<\/code> on extremely high-throughput backup rules or bulk storage policies can exhaust disk\/FortiAnalyzer bandwidth rapidly.<\/li>\n<li><strong>Unchecked Security Profile Overlap:<\/strong> Applying strict IPS sensors alongside heavy proxy profiles without tuning signature pools cause elevated CPU performance bottlenecks.<\/li>\n<\/ol>\n<h2>Production Considerations<\/h2>\n<ul>\n<li><strong>Resource Overhead vs. Inspection Mode:<\/strong> Flow-based processing inspects packet streams as they pass through memory without full protocol buffering, yielding higher throughput and lower latency. Proxy-based inspection buffers full files and payloads before delivering them, offering advanced options (such as payload modification and precise file construction) at the cost of higher memory and CPU utilization. Choose the mode that aligns with your hardware specifications and security baseline.<\/li>\n<li><strong>Hardware Acceleration (SPU Offloading):<\/strong> FortiGate models equipped with CP9 or NP7 Security Processing Units offload intensive cryptographic operations (SSL decryption) and pattern matching. Ensure offloading features remain enabled in production unless explicitly troubleshooting packet drops.<\/li>\n<li><strong>Enterprise PKI Integration:<\/strong> Instead of using self-signed FortiGate CA certificates for SSL inspection, generate a Certificate Signing Request (CSR) from the FortiGate and sign it using your internal Enterprise Subordinate Certificate Authority. Browsers automatically trust certificates issued by established enterprise PKIs.<\/li>\n<li><strong>Exclusion Lists:<\/strong> Sensitive web destinations such as financial institutions, health portals, and strict pin-cert apps (like Zoom or Dropbox) should be added to the SSL inspection bypass list to avoid breaking client connectivity.<\/li>\n<\/ul>\n<h2>Related FortiGate Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-web-filter-configuration-for-corporate-internet-access\/\">FortiGate web filtering<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/\">FortiGate SSL deep inspection<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-session-troubleshooting-with-flow-debug-sessions-and-logs\/\">FortiGate session troubleshooting<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-sd-wan-configuration-for-dual-isp-failover-and-load-balancin\/\">FortiGate SD-WAN configuration<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Applying FortiGate security profiles to standard firewall policies transforms simple access control rules into an enterprise threat-prevention system. By layering Antivirus, Web Filtering, Application Control, IPS, and SSL Deep Inspection onto outbound traffic flows, FortiGate administrators achieve granular visibility and multi-tiered defense at the perimeter. Always ensure endpoint certificate distribution is completed before enabling Deep SSL inspection in production networks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn FortiGate security profiles with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":540,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[29,41,88,44,43,73,89],"class_list":["post-541","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-firewall-tutorial","tag-fortigate","tag-fortigate-security-profiles","tag-fortinet","tag-fortios","tag-intermediate","tag-security-profiles"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate Security Profiles: Firewall Policy Guide<\/title>\n<meta name=\"description\" content=\"Learn how to apply FortiGate security profiles to firewall policies, including antivirus, web filtering, IPS, application control and logging.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Apply FortiGate Security Profiles to Firewall Policies\" \/>\n<meta property=\"og:description\" content=\"Learn how to apply FortiGate security profiles to firewall policies, including antivirus, web filtering, IPS, application control and logging.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-16T05:41:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:03:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"How to Apply FortiGate Security Profiles to Firewall Policies\",\"datePublished\":\"2026-08-16T05:41:03+00:00\",\"dateModified\":\"2026-09-13T23:03:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/\"},\"wordCount\":1927,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png\",\"keywords\":[\"Firewall Tutorial\",\"FortiGate\",\"FortiGate security profiles\",\"Fortinet\",\"FortiOS\",\"Intermediate\",\"Security Profiles\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/\",\"name\":\"FortiGate Security Profiles: Firewall Policy Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png\",\"datePublished\":\"2026-08-16T05:41:03+00:00\",\"dateModified\":\"2026-09-13T23:03:11+00:00\",\"description\":\"Learn how to apply FortiGate security profiles to firewall policies, including antivirus, web filtering, IPS, application control and logging.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png\",\"width\":1200,\"height\":630,\"caption\":\"How to Apply FortiGate Security Profiles to Firewall Policies\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/apply-fortigate-security-profiles-to-firewall-policies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Apply FortiGate Security Profiles to Firewall Policies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate Security Profiles: Firewall Policy Guide","description":"Learn how to apply FortiGate security profiles to firewall policies, including antivirus, web filtering, IPS, application control and logging.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/","og_locale":"en_US","og_type":"article","og_title":"How to Apply FortiGate Security Profiles to Firewall Policies","og_description":"Learn how to apply FortiGate security profiles to firewall policies, including antivirus, web filtering, IPS, application control and logging.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/","og_site_name":"NetworkFix","article_published_time":"2026-08-16T05:41:03+00:00","article_modified_time":"2026-09-13T23:03:11+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"How to Apply FortiGate Security Profiles to Firewall Policies","datePublished":"2026-08-16T05:41:03+00:00","dateModified":"2026-09-13T23:03:11+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/"},"wordCount":1927,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png","keywords":["Firewall Tutorial","FortiGate","FortiGate security profiles","Fortinet","FortiOS","Intermediate","Security Profiles"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/","name":"FortiGate Security Profiles: Firewall Policy Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png","datePublished":"2026-08-16T05:41:03+00:00","dateModified":"2026-09-13T23:03:11+00:00","description":"Learn how to apply FortiGate security profiles to firewall policies, including antivirus, web filtering, IPS, application control and logging.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-apply-fortigate-security-profiles-to-firewall-policies-featured-1.png","width":1200,"height":630,"caption":"How to Apply FortiGate Security Profiles to Firewall Policies"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"How to Apply FortiGate Security Profiles to Firewall Policies"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=541"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/541\/revisions"}],"predecessor-version":[{"id":1564,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/541\/revisions\/1564"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/540"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}