Your auditors want web traffic filtered and logged on site. Encrypted sessions shouldn’t pass through unread — Fortinet FortiProxy is a secure web gateway you run on your own appliance or VM — decrypting, filtering and logging web and DNS traffic on site, with FortiGuard categories, inline CASB and optional DLP, for users inside your network.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Fortinet FortiProxy — the on-premises secure web gateway, with Data Protection and browser isolation as licensed options. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy between users and the internet that decrypts, inspects and filters each web session against your policy.
What consolidation actually replaces, dimension by dimension.
| Dimension | A firewall and DNS names alone | Fortinet FortiProxy |
|---|---|---|
| Where web traffic is checked | By domain name, or not at all | On your own proxy, with TLS decrypted |
| Encrypted sessions | Passed through unread | Deep inspection, with a bypass list |
| DNS filtering | A separate resolver service | In the same bundle and policy |
| SaaS uploads | Allowed or blocked by domain | Per activity and per tenant, inline |
| Logs for CERT-In | Scattered across firewall and resolver | Proxy logs on FortiAnalyzer or syslog |
| What it is NOT | — | A cloud service, a roaming agent or API CASB |
The cheapest test is one office: point it at a VM in monitor mode for two weeks, then compare what it would have blocked with what users actually need.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A 400G, 2000G or 4000G appliance, or a VM on ESXi, KVM, Hyper-V, AWS, Azure or GCP, ends each web session as an explicit, transparent, WCCP or routed proxy.
Deep-inspection profiles decrypt HTTPS with a CA certificate you choose and push to devices; address and category allowlists exempt banking, health and pinned apps.
Web, video and DNS ratings, antivirus, IPS and botnet feeds come from FortiGuard Labs; DNS filtering needs FortiGuard DNS lookups, so Fortinet’s cloud stays in the path.
Logs go to the box, FortiAnalyzer or syslog; files can go to FortiSandbox or FortiNDR, and ICAP or WCCP links it to a FortiGate, a cache or third-party DLP.
A proxy on hardware you rack — sessions decrypted on site, rated by FortiGuard, logged to your own FortiAnalyzer.
FortiProxy sits between your users and the internet, opens encrypted sessions and filters them on hardware you control.
Explicit proxy with hosted PAC files, transparent inline, WCCP or policy-based routing, so it can sit behind your firewall without re-cabling.
Appliances offload SSL inspection to hardware; profiles set the CA, the protocols, the ports and which categories skip decryption.
DNS filter profiles block by FortiGuard category, flag newly registered and parked domains, and catch DNS tunnelling and DGA domains.
Hundreds of millions of URLs are rated into more than 90 categories, with video filtering and rating overrides for chosen groups.
Application control knows more than 3,000 applications and can allow a site while blocking one action in it, such as posting.
Inline CASB blocks uploads, downloads or logins per SaaS app and admits only your corporate tenant; the policy must decrypt.
FortiGuard antivirus, IPS, botnet blocking and content disarm run in the bundle; suspect files go to FortiSandbox Cloud.
The optional Data Protection Service adds DLP with exact data match and OCR, plus AI image rating for weapons, gore or adult content.
An optional licence runs Chrome, Edge or Firefox on Windows inside a local Docker container, without needing SSL inspection.
OCR-based data protection, FortiProxy as an ICAP server behind a FortiGate, and the product overview. All from Fortinet’s official channel, recorded in 2023 and 2024.
OCR-based DLP and AI image analysis from the optional Data Protection Service, shown on live traffic.
A FortiGate hands web content to FortiProxy over ICAP, for estates that keep the firewall in front.
The broad tour: proxy modes, FortiGuard filtering, inspection and where FortiProxy sits in the network.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
The required SWG Protection Bundle puts web and video filtering, DNS filtering, application control, antivirus, IPS, botnet blocking and cloud sandboxing on one appliance. SEBI’s CSCRF names proxy servers (4.b), web filters (4.c) and DNS filtering (4.e); FortiProxy answers all three under one policy.
Because the proxy is hardware or a VM you place, decrypted traffic is inspected on your own site and logs land on the box, a FortiAnalyzer or your syslog server. That suits CERT-In’s 180-day log retention and its 2023 guidance that government offices reach the internet only through a proxy.
It speaks what older proxies speak — explicit mode with PAC files, WCCP, ICAP, NTLM and Kerberos — and adds caching and WAN optimisation, so a ProxySG-era design can move across. Seats are shared across appliances and VMs, and VDOMs give business units separate policy.
There is no roaming agent: a laptop off the network is filtered only if you publish the proxy or bring it home over VPN, and FortiSASE is Fortinet’s answer for that. CASB is inline only, with no API scanning. There is no public price, and 2025–26 brought exploited admin-login flaws to patch.
Count users per site, decide explicit, transparent or WCCP, and size an appliance or VM against Fortinet’s user ratings.
Choose the inspection CA, push it to managed devices, and list banking, health and pinned apps that must bypass decryption.
Point one site at the proxy, turn on web and DNS filter profiles in monitor mode, and compare blocks against real traffic.
Add inline CASB tenant rules for your SaaS apps, then Data Protection rules if licensed, and route logs to FortiAnalyzer.
Extend to every site on 7.6, lock the admin interface down, and decide how off-network laptops will be filtered.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We put a 2000G behind the core firewall on WCCP. Nothing was re-cabled, and the old proxy’s PAC file kept working.”
“OCR in the DLP caught scanned identity cards going to personal webmail. Our keyword rules had missed them for months.”
“Deep inspection broke two banking portals and a tax utility on day one. Build the bypass list before you switch it on.”
“Tenant control let us allow our own Microsoft 365 while stopping staff signing in to personal accounts at work.”
“Remote staff were the gap. With no roaming agent we published a PAC file, and getting authentication right took weeks.”
“The January advisories meant an out-of-hours upgrade on both HA nodes. Keep the admin port off the internet.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Device plus 500-user seat lots; quote only.
The grid nobody publishes — how much of the inspection runs on hardware you control vs how deep it looks into each session.
On your hardware; full TLS, DNS filter, inline CASB, optional DLP.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Symantec Edge SWG, Zscaler Internet Access, Netskope Next Gen SWG, Cisco Umbrella and Fortinet FortiSASE — on deployment, filtering layer, TLS, roaming, CASB, price, scale and India.
| Dimension | Fortinet FortiProxy | Symantec Edge SWG | Zscaler Internet Access | Netskope Next Gen SWG | Cisco Umbrella | Fortinet FortiSASE |
|---|---|---|---|---|---|---|
| What it is | On-prem SWG appliance | ProxySG, renamed | Cloud inline proxy | Cloud SWG, app-aware | DNS first, proxy tiers | Fortinet’s cloud SSE |
| Deployment | Appliance or VM | Appliance, VM or cloud | Cloud only | NewEdge cloud | Resolvers + cloud proxy | Cloud + FortiClient |
| Filtering layer | Proxy plus DNS filter | Proxy | Proxy, no DNS tier | Proxy by app instance | DNS, then proxy | Cloud proxy + DNS filter |
| TLS inspection | Full, in hardware | Full, SSL Visibility | Full inspection | Full, instance-aware | Selective at SIG | Full deep inspection |
| Off-network users | No roaming agent | Through Cloud SWG | Client Connector | Netskope client | Roaming module | FortiClient agent |
| CASB | Inline only | Cloud app controls | Inline and API | Both modes, documented | API-based | Inline |
| Pricing model | Device + user seats | Per-user subscription | Per user, by edition | Per user, platform | Per user, four tiers | Per user, by tier |
| Published entry price | Not published | No public price | ~$6–12/user/mo | Quoted in platform deal | From ~$2.25/user/mo | Quote (UK list £78+) |
| Included vs add-on | DLP, RBI are extra | Components apart | Editions and add-ons | Platform modules | Proxy costs a tier | Tier sets the scope |
| Scale | 60,000 users (rated) | Sized by appliance | Large estates | Scales in NewEdge | Scales by resolver | Verified above 5,000 |
| Integrations | Fabric, ICAP, WCCP | Management Center | One cloud console | Netskope One console | Umbrella dashboard | FortiSASE console |
| Identity and certification | SAML, LDAP, Kerberos | FIPS 140-3, CC | IdP via SAML | IdP plus device context | AD or SAML, by tier | SAML, EMS posture |
| India | Your own site | Mumbai and Delhi PoPs | Four Indian cities | Eight Indian DCs | Mumbai and Chennai | PoPs not documented |
| Best fit | On-site inspection | ProxySG renewals | Deepest cloud proxy | App-instance control | Cheap DNS everywhere | FortiGate, gone remote |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Fortinet FortiProxy is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the proxy; IT staff-hour cost). Estimates model the IT time spent per user each year on web-borne malware clean-ups, block-list upkeep and one-off access exceptions, at an assumed 1.5 hours per user a year, with 70% of it removed by category filtering, inspection and one policy. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Fortinet publishes no FortiProxy price. You buy a 400G, 2000G or 4000G appliance or a yearly VM subscription, then the required SWG Protection Bundle — web, video and DNS filtering, application control, antivirus, IPS, botnet blocking and cloud sandboxing — sold as a yearly subscription in 500-user seat lots that can be shared across your devices. Data Protection (DLP with OCR), client browser isolation and extra VDOMs are optional licences. Without the bundle the box only caches and optimises WAN traffic. TechBag sizes your sites first, then quotes in INR with GST.
Best for web, DNS and threat filtering on site
Best for a broader rollout
Best for data protection and risky browsing
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many users sit behind each site? Map them to the 400G, 2000G, 4000G or a VM using Fortinet’s user ratings.
Can you push the inspection CA to every managed device, and who owns the bypass list for pinned and banking apps?
Explicit with PAC files, transparent inline, WCCP or policy routing? Which fits your current firewall and cabling?
How will laptops off the network be filtered — a published proxy, a VPN back home, or FortiSASE alongside?
Is inline tenant and activity control enough, or do you also need API scanning of data already stored in SaaS apps?
Which applies — SEBI CSCRF 4.b, 4.c and 4.e, CERT-In’s 180-day logs, or government proxy-only internet rules?
Will you run 7.6.6 or later, keep the admin interface off the internet, and leave FortiCloud SSO off unless needed?
Does the quote list the device, SWG bundle seat lots, Data Protection, isolation, VDOMs and support term in INR with GST?
Count your users per site and plan the inspection certificate first, or let a TechBag advisor size the appliance, draft the bypass list and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.