🛡️ ToastFort

NGFW mode: profile vs policy

profile-based · policy-based

whether application control and web-category matching happen inside a security profile, or as first-class firewall-policy match criteria

A system-wide setting (with flow-based inspection). Changes how you build policies for app/URL control.

How it is read

NGFW profile-based (default)

mode

Traditional model: the policy matches on the classic 5-tuple + user/device, then you attach security profiles (AppControl, Web Filter, AV, IPS). Application and URL decisions live inside those profiles. Works with both flow and proxy inspection.

NGFW policy-based

mode

Applications and URL categories become direct match criteria on the firewall policy itself — you write a policy that says "allow Salesforce" or "deny Streaming Media". Requires a central SSL-SSH inspection policy and flow-based inspection. Fewer profiles to manage, but a different mental model and less granular per-policy AV/IPS control.

In the corpus (2)

Firewall policies & authentication

Content inspection