> Chapter 20 - Parallel Path Processing - Life of a Packet > Comparison of inspection layers
Comparison of inspection types
The tables in this section show how different security functions map to different inspection types.
Mapping security functions to inspection types
The table below lists FortiOS security functions and shows whether they are applied during stateful inspection, flow-based inspection or proxy-based inspection.
FortiOS security functions and inspection types
Security Function | Stateful Inspection | Flow-based inspection | Proxy-based inspection |
---|---|---|---|
Firewall | yes | ||
IPsec VPN | yes | ||
Traffic Shaping | yes | ||
User Authentication | yes | ||
Management Traffic | yes | ||
SSL VPN | yes | ||
IPS | yes | ||
Antivirus | yes | yes | |
Application Control | yes | ||
Web filtering | yes | yes | |
DLP | yes | yes | |
Email Filtering | yes | ||
VoIP inspection | yes |
||
ICAP | yes |
More informaion about inspection methods
The three inspection methods each have their own strengths and weaknesses. The following table looks at all three methods side-by-side.
Inspection methods comparison
Feature | Stateful | Flow | Proxy |
---|---|---|---|
Inspection unit per session | first packet | selected packets | complete content |
Memory, CPU required | low | medium | high |
Level of threat protection | good | better | best |
Authentication | yes | ||
IPsec and SSL VPN | yes | ||
Antivirus protection | yes | yes | |
Web Filtering | yes | yes | |
Data Leak Protection (DLP) | yes | yes | |
Application control | yes | ||
IPS | yes | ||
Delay in traffic | minor | no | small |
Reconstruct entire content | no | yes |