Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FPROXY

FortiProxy

Dedicated secure web gateway — explicit proxy, DLP and SSL inspection at scale

Licensing
By appliance model or virtual instance
Deployment
Explicit proxy or transparent
Capabilities
URL filtering, DLP, AV, SSL inspection, sandbox integration

FortiProxy handles deep outbound web inspection — URL filtering, DLP, antivirus, content analysis and SSL inspection — at a scale that would otherwise consume a firewall's whole capacity budget. It supports explicit proxy and transparent deployment and integrates with FortiSandbox.

Is this the right model?

Where it fits — and where it stops fitting

SSL inspection of all outbound web traffic is the single most expensive thing you can ask a FortiGate to do. Moving it to a purpose-built proxy keeps the firewall doing firewall work, and for a few thousand users is usually cheaper than up-sizing the firewall. If a FortiGate's web filter is already enough, use it and save the appliance.

Highlights

  • Offloads SSL inspection from the firewall
  • Explicit proxy with per-user authentication and full logging
  • Outbound DLP for regulated data
  • Submits unknown downloads to FortiSandbox

Typical deployments

  • Education and government requiring explicit proxy with per-user logs
  • Inspecting all outbound HTTPS for thousands of users
  • Outbound content inspection for PHI or cardholder data
Buying guidance

What to work out first

FortiProxy is a dedicated secure web gateway for environments that need deep outbound web inspection: URL filtering, DLP, antivirus, content analysis and SSL inspection at a scale that would otherwise consume a firewall's whole capacity budget.

The case for a separate appliance is straightforward — SSL inspection of all outbound web traffic is the single most expensive thing you can ask a FortiGate to do. Moving it to a purpose-built proxy keeps the firewall doing firewall work.

It supports explicit proxy and transparent deployment, and integrates with FortiSandbox for detonation of unknown downloads.

Questions worth answering before you order

Do you need explicit proxy specifically?

Some environments — education, government, regulated enterprises — require explicit proxy with per-user authentication and full logging. If a FortiGate's web filter is enough, use it and save the appliance.

How much SSL inspection?

This is the sizing number. If you are inspecting all outbound HTTPS for thousands of users, a dedicated proxy is usually cheaper than up-sizing the firewall.

Is DLP a requirement?

Outbound content inspection for regulated data is often the real driver and it needs the policy work scoped, not just the box quoted.

Specifications

What this includes

Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.

What you are buying

What you are buying
LicensingBy appliance model or virtual instance
DeploymentExplicit proxy or transparent
CapabilitiesURL filtering, DLP, AV, SSL inspection, sandbox integration

How this is sized

Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment — tell us the numbers and we will work it through with you.

How this is sized
LicensingBy appliance model or virtual instance

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare