🛡️ ToastFort

Concept glossary

Key terms, each followed across the corpus and — where the sources disagree — across the voices that construe it differently.

Inspection mode: flow vs proxy flow-based · proxy-based how the FortiGate buffers and scans traffic for a security profile — packet-by-packet, or by reconstructing the whole object first 2 passages · 2 readings NGFW mode: profile vs policy profile-based · policy-based whether application control and web-category matching happen inside a security profile, or as first-class firewall-policy match criteria 2 passages · 2 readings NAT: central vs policy central NAT · policy-based NAT whether NAT is configured on each firewall policy, or in separate central SNAT / DNAT tables evaluated independently 1 passages · 2 readings SSL inspection: certificate vs deep certificate-inspection · deep-inspection · SSL-SSH profile how much of an HTTPS session the FortiGate can actually see 2 passages · 2 readings FSSO: agent vs agentless Fortinet Single Sign-On · DC agent · collector agent · polling mode how the FortiGate learns which user is behind an IP so identity-based policies work without a login prompt 1 passages · 2 readings local-in policy vs firewall policy traffic TO the FortiGate is governed by local-in policies; traffic THROUGH it by firewall policies — two separate engines 2 passages HA primary election (FGCP) & override the ordered tie-break that picks the primary unit in an FGCP cluster, and what the override flag changes 1 passages Route selection order policy routes → the FIB (most specific prefix, then lowest distance, then lowest priority, then ECMP) → SD-WAN rules sit on top for their members 2 passages Conserve mode a memory-protection state the FortiGate enters at ~88% RAM and leaves at ~82%, during which it stops accepting new proxy-inspected sessions 1 passages Security Fabric (CSF) roles a tree of FortiGates (and other Fortinet devices) sharing topology and telemetry; one root, the rest downstream, connected on TCP 8013 1 passages