FortiProxy
FortiProxy: Secure Web Gateway with SSL inspection. URL filtering 90+ categories, CASB, DLP, video caching. Explicit and transparent proxy.

Key Features
- SSL/TLS deep inspection with hardware acceleration
- URL filtering 90+ categories
- Application control 4,000+ applications
- Data Loss Prevention (DLP)
- CASB for SaaS visibility
Table of Contents
Why do you need FortiProxy?
85% of malware uses encrypted traffic. SSL inspection on firewall burdens CPU and reduces throughput. URL filtering on UTM can’t keep up with 4,000+ new malicious URLs daily.
FortiProxy is a dedicated Secure Web Gateway with hardware-accelerated SSL inspection. Specialized for proxy workloads, it provides higher performance than UTM, and 90+ URL filtering categories and CASB give full control over web traffic.
How does it work?
SSL/TLS Deep Inspection
Hardware-accelerated decryption:
- TLS 1.3 full support
- Certificate validation and pinning handling
- Dedicated SSL processors
- Selective inspection policies
- Certificate exception handling
URL Filtering
FortiGuard Web Filtering:
- 90+ categories of content
- Real-time categorization
- Custom categories and overrides
- Safe Search enforcement
- Quota management
Application Control
Granular SaaS and web app control:
- 4,000+ recognized applications
- Function-level control (e.g., Facebook chat vs upload)
- Bandwidth throttling
- Time-based policies
- Shadow IT detection
Key Features
CASB Capabilities
- SaaS application discovery
- Shadow IT identification
- Data protection in cloud apps
- Access control policies
- Usage analytics
Data Loss Prevention
- Content inspection
- Regulatory templates (GDPR, HIPAA, PCI)
- Custom dictionaries
- File type filtering
- Fingerprinting
Caching
- Web content caching
- Video streaming cache
- Software update caching
- Bandwidth savings 30-50%
- User experience improvement
Authentication
- LDAP/Active Directory
- SAML/OAuth
- Kerberos/NTLM
- Captive portal
- Multi-factor (with FortiAuthenticator)
Deployment Modes
Explicit Proxy:
- PAC file or browser config
- WPAD auto-discovery
- User authentication
- Full visibility
Transparent Proxy:
- WCCP integration
- Policy-based routing
- No client changes
- Inline deployment
Reverse Proxy:
- Web application protection
- Load balancing
- SSL offloading
- WAF capabilities
Deployment Models
| Model | Users | SSL Inspection | Use Case |
|---|---|---|---|
| VM | Variable | Variable | Cloud |
| 400G | 1,500 | 1 Gbps | SMB |
| 2000G | 6,000 | 3 Gbps | Mid-size |
| 4000G | 15,000 | 8 Gbps | Enterprise |
FortiProxy vs FortiGate Proxy
| FortiProxy | FortiGate Proxy | |
|---|---|---|
| Purpose | Dedicated SWG | Part of NGFW |
| Performance | Optimized | General purpose |
| Features | Full SWG + caching | Basic proxy |
| Use case | Large scale proxy | Integrated security |
Who is it for?
- Enterprises with heavy web traffic and SSL inspection requirements
- Organizations needing dedicated proxy performance
- Companies with CASB and DLP requirements
- Distributed environments with caching needs
Benefits
For IT: Dedicated performance, video caching, bandwidth savings
For security: Full SSL visibility, CASB, DLP, advanced URL filtering
For business: Productivity control, compliance, optimized bandwidth costs
Specifications
| SSL inspection | Hardware accelerated |
| URL categories | 90+ |
| Applications | 4,000+ |
| Deployment | Explicit, transparent, reverse |
FAQ
How does FortiProxy differ from proxy in FortiGate? FortiProxy is a dedicated SWG platform with optimized performance, caching, advanced features. FortiGate has basic proxy.
How does SSL inspection work? Hardware-accelerated decrypt-inspect-reencrypt. Certificate generation for clients, validation for servers.
Can I cache video? Yes. YouTube, Microsoft Stream, others. Bandwidth savings 30-50% for repeated content.
How does URL filtering work? FortiGuard 90+ categories, real-time updates, custom categories, Safe Search, quota per user/group.
What is CASB? Cloud Access Security Broker - visibility and control over SaaS applications like Office 365, Salesforce.
Does FortiProxy support WCCP? Yes. Transparent proxy with WCCP redirection from Cisco and other vendors.
How does DLP work? Content inspection, regex patterns, dictionaries, compliance templates. Block or log sensitive data.
Can I use it with FortiGate? Yes. Complementary deployment - FortiGate for firewall, FortiProxy for dedicated web security.
How does authentication work? LDAP, AD, SAML, Kerberos, NTLM. Captive portal, FortiAuthenticator for MFA.
How does support work? Fortinet 24/7 TAC. nFlo as partner offers SWG deployment and policy optimization.
Inquire about FortiProxy
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Firewall and NGFW Implementation
Cybersecurity
Effective network protection against threats. Implementation and configuration in 2 weeks.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist