Concept glossary
Key terms, each followed across the corpus and — where the sources disagree — across the voices that construe it differently.
Inspection mode: flow vs proxy
flow-based · proxy-based
how the FortiGate buffers and scans traffic for a security profile — packet-by-packet, or by reconstructing the whole object first
2 passages · 2 readings
NGFW mode: profile vs policy
profile-based · policy-based
whether application control and web-category matching happen inside a security profile, or as first-class firewall-policy match criteria
2 passages · 2 readings
NAT: central vs policy
central NAT · policy-based NAT
whether NAT is configured on each firewall policy, or in separate central SNAT / DNAT tables evaluated independently
1 passages · 2 readings
SSL inspection: certificate vs deep
certificate-inspection · deep-inspection · SSL-SSH profile
how much of an HTTPS session the FortiGate can actually see
2 passages · 2 readings
FSSO: agent vs agentless
Fortinet Single Sign-On · DC agent · collector agent · polling mode
how the FortiGate learns which user is behind an IP so identity-based policies work without a login prompt
1 passages · 2 readings
local-in policy vs firewall policy
traffic TO the FortiGate is governed by local-in policies; traffic THROUGH it by firewall policies — two separate engines
2 passages
HA primary election (FGCP) & override
the ordered tie-break that picks the primary unit in an FGCP cluster, and what the override flag changes
1 passages
Route selection order
policy routes → the FIB (most specific prefix, then lowest distance, then lowest priority, then ECMP) → SD-WAN rules sit on top for their members
2 passages
Conserve mode
a memory-protection state the FortiGate enters at ~88% RAM and leaves at ~82%, during which it stops accepting new proxy-inspected sessions
1 passages
Security Fabric (CSF) roles
a tree of FortiGates (and other Fortinet devices) sharing topology and telemetry; one root, the rest downstream, connected on TCP 8013
1 passages