FortiProxy
Dedicated secure web gateway, explicit proxy, DLP and SSL inspection at scale
- Licensing
- By appliance model or virtual instance
- Deployment
- Explicit proxy or transparent
- Capabilities
- URL filtering, DLP, AV, SSL inspection, sandbox integration
FortiProxy handles deep outbound web inspection, URL filtering, DLP, antivirus, content analysis and SSL inspection, at a scale that would otherwise consume a firewall's whole capacity budget. It supports explicit proxy and transparent deployment and integrates with FortiSandbox.
Where it fits, and where it stops fitting
SSL inspection of all outbound web traffic is the single most expensive thing you can ask a FortiGate to do. Moving it to a purpose-built proxy keeps the firewall doing firewall work, and for a few thousand users is usually cheaper than up-sizing the firewall. If a FortiGate's web filter is already enough, use it and save the appliance.
Highlights
- Offloads SSL inspection from the firewall
- Explicit proxy with per-user authentication and full logging
- Outbound DLP for regulated data
- Submits unknown downloads to FortiSandbox
Typical deployments
- Education and government requiring explicit proxy with per-user logs
- Inspecting all outbound HTTPS for thousands of users
- Outbound content inspection for PHI or cardholder data
What to work out first
FortiProxy is a dedicated secure web gateway for environments that need deep outbound web inspection: URL filtering, DLP, antivirus, content analysis and SSL inspection at a scale that would otherwise consume a firewall's whole capacity budget.
The case for a separate appliance is straightforward, SSL inspection of all outbound web traffic is the single most expensive thing you can ask a FortiGate to do. Moving it to a purpose-built proxy keeps the firewall doing firewall work.
It supports explicit proxy and transparent deployment, and integrates with FortiSandbox for detonation of unknown downloads.
Questions worth answering before you order
Do you need explicit proxy specifically?
Some environments, education, government, regulated enterprises, require explicit proxy with per-user authentication and full logging. If a FortiGate's web filter is enough, use it and save the appliance.
How much SSL inspection?
This is the sizing number. If you are inspecting all outbound HTTPS for thousands of users, a dedicated proxy is usually cheaper than up-sizing the firewall.
Is DLP a requirement?
Outbound content inspection for regulated data is often the real driver and it needs the policy work scoped, not just the box quoted.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | By appliance model or virtual instance |
|---|---|
| Deployment | Explicit proxy or transparent |
| Capabilities | URL filtering, DLP, AV, SSL inspection, sandbox integration |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | By appliance model or virtual instance |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.