Talk to us
by FortinetTechBag Intel Page

Fortinet FortiProxy

Your auditors want web traffic filtered and logged on site. Encrypted sessions shouldn’t pass through unread — Fortinet FortiProxy is a secure web gateway you run on your own appliance or VM — decrypting, filtering and logging web and DNS traffic on site, with FortiGuard categories, inline CASB and optional DLP, for users inside your network.

On-premises proxy with full TLS inspectionDNS filtering and inline CASB includedQuoted; seats in 500-user lots

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Fortinet prints no FortiProxy price; user seats come in 500-user lots on top of the device
Quote
Layer
A full proxy with TLS decryption, and DNS filter profiles in the same SWG Protection Bundle
Proxy + DNS
Roaming
Off-network laptops reach it only through a published PAC file or a VPN back to the office
No agent
India
The proxy and its logs run on hardware or VMs you place; FortiGuard lookups go to Fortinet’s cloud
Your site

Quick answer

FortiProxy is Fortinet’s on-premises secure web gateway: an appliance or VM that runs as an explicit or transparent proxy and applies FortiGuard web, video and DNS filtering, full TLS inspection, inline CASB, antivirus and IPS, with DLP optional. You buy the device plus a yearly SWG Protection Bundle in 500-user seat lots, on quote. Traffic and logs stay on hardware you place in India, but there is no roaming agent for laptops off the network. Read more ↓ Show less ↑
Part 01 · Orient

The Fortinet platform family

This page covers Fortinet FortiProxy — the on-premises secure web gateway, with Data Protection and browser isolation as licensed options. The rest:

Quick facts

30-second orientation
Product
On-premises secure web gateway: explicit, transparent, WCCP or policy-routed proxy
Maker
Fortinet, Sunnyvale, California; founded 2000 by Ken and Michael Xie; CEO Ken Xie
Status
Sold today; 7.6 is the current branch (7.6.7), and 7.0 and 7.2 no longer get every fix
Price
Not published; the device plus a yearly SWG Protection Bundle, quoted in 500-user lots
Licence
Hardware or a VM subscription, plus the required SWG bundle; DLP, isolation and VDOMs optional
Capacity
Vendor-rated: 6,000 users on a 400G, 60,000 on a 4000G, and 500 to 50,000 on VMs
Inspection
Full TLS deep inspection, hardware-assisted on appliances, with category and address bypass lists
CASB
Inline only: per-activity, tenant and safe-search control, on policies using deep inspection
India
Proxy, traffic and logs sit on hardware you place; Fortinet’s India office is in Bengaluru
In India via
TechBag — sizing, bypass-list planning, quote in INR with GST, a pilot on one site
Part 02 · Learn

Understand secure web gateways before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a secure web gateway?

A proxy between users and the internet that decrypts, inspects and filters each web session against your policy.

A firewall and DNS names alone vs Fortinet FortiProxy — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA firewall and DNS names aloneFortinet FortiProxy
Where web traffic is checkedBy domain name, or not at allOn your own proxy, with TLS decrypted
Encrypted sessionsPassed through unreadDeep inspection, with a bypass list
DNS filteringA separate resolver serviceIn the same bundle and policy
SaaS uploadsAllowed or blocked by domainPer activity and per tenant, inline
Logs for CERT-InScattered across firewall and resolverProxy logs on FortiAnalyzer or syslog
What it is NOT—A cloud service, a roaming agent or API CASB

The cheapest test is one office: point it at a VM in monitor mode for two weeks, then compare what it would have blocked with what users actually need.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where web sessions are terminated

Proxy

FortiProxy appliance or VM

A 400G, 2000G or 4000G appliance, or a VM on ESXi, KVM, Hyper-V, AWS, Azure or GCP, ends each web session as an explicit, transparent, WCCP or routed proxy.

02
How encrypted traffic is opened

Decrypt

SSL/SSH inspection profiles

Deep-inspection profiles decrypt HTTPS with a CA certificate you choose and push to devices; address and category allowlists exempt banking, health and pinned apps.

03
Where ratings and signatures come from

Verdicts

FortiGuard services

Web, video and DNS ratings, antivirus, IPS and botnet feeds come from FortiGuard Labs; DNS filtering needs FortiGuard DNS lookups, so Fortinet’s cloud stays in the path.

04
Where logs and files go next

Fabric

FortiAnalyzer, FortiSandbox, ICAP

Logs go to the box, FortiAnalyzer or syslog; files can go to FortiSandbox or FortiNDR, and ICAP or WCCP links it to a FortiGate, a cache or third-party DLP.

A proxy on hardware you rack — sessions decrypted on site, rated by FortiGuard, logged to your own FortiAnalyzer.

Part 03 · Evaluate

Nine capabilities. Inspect, control, protect.

FortiProxy sits between your users and the internet, opens encrypted sessions and filters them on hardware you control.

Inspect
Proxy modes

Explicit, transparent or routed

Explicit proxy with hosted PAC files, transparent inline, WCCP or policy-based routing, so it can sit behind your firewall without re-cabling.

Inspect
TLS

Decryption in hardware

Appliances offload SSL inspection to hardware; profiles set the CA, the protocols, the ports and which categories skip decryption.

Inspect
DNS

DNS filtering in the bundle

DNS filter profiles block by FortiGuard category, flag newly registered and parked domains, and catch DNS tunnelling and DGA domains.

Control
Web filter

90+ FortiGuard categories

Hundreds of millions of URLs are rated into more than 90 categories, with video filtering and rating overrides for chosen groups.

Control
Applications

3,000+ apps, by action

Application control knows more than 3,000 applications and can allow a site while blocking one action in it, such as posting.

Control
Inline CASB

Your tenant, not theirs

Inline CASB blocks uploads, downloads or logins per SaaS app and admits only your corporate tenant; the policy must decrypt.

Protect
Threats

AV, IPS and a sandbox

FortiGuard antivirus, IPS, botnet blocking and content disarm run in the bundle; suspect files go to FortiSandbox Cloud.

Protect
Data Protection

DLP that reads images

The optional Data Protection Service adds DLP with exact data match and OCR, plus AI image rating for weapons, gore or adult content.

Protect
Isolation

Browser in a container

An optional licence runs Chrome, Edge or Firefox on Windows inside a local Docker container, without needing SSL inspection.

See it, don’t just read it

Watch Fortinet FortiProxy in action

OCR-based data protection, FortiProxy as an ICAP server behind a FortiGate, and the product overview. All from Fortinet’s official channel, recorded in 2023 and 2024.

Fortinet (official)·Demo, 9 min, October 2024

AI-Powered Content Analysis and Data Protection with OCR with DLP | FortiProxy

OCR-based DLP and AI image analysis from the optional Data Protection Service, shown on live traffic.

Fortinet (official)·Demo, 11 min, October 2024

FortiProxy as ICAP Server Integration with FortiGate | Secure Web Gateway

A FortiGate hands web content to FortiProxy over ICAP, for estates that keep the firewall in front.

Fortinet (official)·Overview, 9 min, April 2023

Enterprise-Class Protection Against Internet-Borne Threats | FortiProxy

The broad tour: proxy modes, FortiGuard filtering, inspection and where FortiProxy sits in the network.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Fortinet FortiProxy

Most web traffic is encrypted. FortiProxy opens it on your own hardware.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Proxy, web filter and DNS filter in one box

The required SWG Protection Bundle puts web and video filtering, DNS filtering, application control, antivirus, IPS, botnet blocking and cloud sandboxing on one appliance. SEBI’s CSCRF names proxy servers (4.b), web filters (4.c) and DNS filtering (4.e); FortiProxy answers all three under one policy.

02

Decryption and logs stay on your premises

Because the proxy is hardware or a VM you place, decrypted traffic is inspected on your own site and logs land on the box, a FortiAnalyzer or your syslog server. That suits CERT-In’s 180-day log retention and its 2023 guidance that government offices reach the internet only through a proxy.

03

A path off an ageing proxy estate

It speaks what older proxies speak — explicit mode with PAC files, WCCP, ICAP, NTLM and Kerberos — and adds caching and WAN optimisation, so a ProxySG-era design can move across. Seats are shared across appliances and VMs, and VDOMs give business units separate policy.

04

Where it stops

There is no roaming agent: a laptop off the network is filtered only if you publish the proxy or bring it home over VPN, and FortiSASE is Fortinet’s answer for that. CASB is inline only, with no API scanning. There is no public price, and 2025–26 brought exploited admin-login flaws to patch.

The idea
A web gateway on your own hardware
The reach
Proxy, DNS filter and inline CASB
The price
Quoted; seats in 500-user lots
Proof, not promises

The numbers behind the platform

60000 users
the vendor-rated ceiling for one FortiProxy 4000G appliance; the 1U 400G is rated for 6,000
— Vendor
90+ categories
FortiGuard web-filter categories, covering hundreds of millions of rated URLs
— Vendor
3000+ apps
applications FortiProxy’s application control can identify and govern by action
— Vendor
500 users
the seat lot the SWG Protection Bundle is sold in, shared across your devices
— Vendor
15 Gbps
the top proxy speed in Fortinet’s 2024 data sheet, measured in its own lab
— Vendor
180 days
CERT-In’s log retention period; proxy logs can sit on FortiAnalyzer or syslog
— Regulator

What your FortiProxy rollout looks like

Week 1Model

Count users and pick the mode

Count users per site, decide explicit, transparent or WCCP, and size an appliance or VM against Fortinet’s user ratings.

Week 2Decide

Plan the certificate first

Choose the inspection CA, push it to managed devices, and list banking, health and pinned apps that must bypass decryption.

Week 3Pilot

Pilot one office

Point one site at the proxy, turn on web and DNS filter profiles in monitor mode, and compare blocks against real traffic.

Month 2Prove

Turn on CASB and DLP

Add inline CASB tenant rules for your SaaS apps, then Data Protection rules if licensed, and route logs to FortiAnalyzer.

Month 3Commit

Roll out, patch, plan roaming

Extend to every site on 7.6, lock the admin interface down, and decide how off-network laptops will be filtered.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
47+ reviews*
82% would recommend
Inspection depth4.4
Filtering and categories4.3
Deployment flexibility4.3
Ease of management3.8
Value for money3.9
5★
46%
4★
34%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We put a 2000G behind the core firewall on WCCP. Nothing was re-cabled, and the old proxy’s PAC file kept working.”
Network Architect
BFSI
Financial Services
“OCR in the DLP caught scanned identity cards going to personal webmail. Our keyword rules had missed them for months.”
Information Security Manager
Financial Services
Manufacturing
“Deep inspection broke two banking portals and a tax utility on day one. Build the bypass list before you switch it on.”
Systems Administrator
Manufacturing
Healthcare
“Tenant control let us allow our own Microsoft 365 while stopping staff signing in to personal accounts at work.”
IT Manager
Healthcare
Education
“Remote staff were the gap. With no roaming agent we published a PAC file, and getting authentication right took weeks.”
Head of IT
Education
Government
“The January advisories meant an out-of-hours upgrade on both HA nodes. Keep the admin port off the internet.”
Security Engineer
Government
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Secure Web & DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Fortinet FortiProxyThis page

Device plus 500-user seat lots; quote only.

Grid 02 · The architecture

On-Site Control × Inspection Depth

The grid nobody publishes — how much of the inspection runs on hardware you control vs how deep it looks into each session.

Deep cloud proxiesDeep and on-siteLight cloud filtersOn-site but shallow
Fortinet FortiProxyThis page

On your hardware; full TLS, DNS filter, inline CASB, optional DLP.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

FortiProxy vs the secure web gateway field

Against Symantec Edge SWG, Zscaler Internet Access, Netskope Next Gen SWG, Cisco Umbrella and Fortinet FortiSASE — on deployment, filtering layer, TLS, roaming, CASB, price, scale and India.

DimensionFortinet FortiProxySymantec Edge SWGZscaler Internet AccessNetskope Next Gen SWGCisco UmbrellaFortinet FortiSASE
What it isOn-prem SWG applianceProxySG, renamedCloud inline proxyCloud SWG, app-awareDNS first, proxy tiersFortinet’s cloud SSE
DeploymentAppliance or VMAppliance, VM or cloudCloud onlyNewEdge cloudResolvers + cloud proxyCloud + FortiClient
Filtering layerProxy plus DNS filterProxyProxy, no DNS tierProxy by app instanceDNS, then proxyCloud proxy + DNS filter
TLS inspectionFull, in hardwareFull, SSL VisibilityFull inspectionFull, instance-awareSelective at SIGFull deep inspection
Off-network usersNo roaming agentThrough Cloud SWGClient ConnectorNetskope clientRoaming moduleFortiClient agent
CASBInline onlyCloud app controlsInline and APIBoth modes, documentedAPI-basedInline
Pricing modelDevice + user seatsPer-user subscriptionPer user, by editionPer user, platformPer user, four tiersPer user, by tier
Published entry priceNot publishedNo public price~$6–12/user/moQuoted in platform dealFrom ~$2.25/user/moQuote (UK list £78+)
Included vs add-onDLP, RBI are extraComponents apartEditions and add-onsPlatform modulesProxy costs a tierTier sets the scope
Scale60,000 users (rated)Sized by applianceLarge estatesScales in NewEdgeScales by resolverVerified above 5,000
IntegrationsFabric, ICAP, WCCPManagement CenterOne cloud consoleNetskope One consoleUmbrella dashboardFortiSASE console
Identity and certificationSAML, LDAP, KerberosFIPS 140-3, CCIdP via SAMLIdP plus device contextAD or SAML, by tierSAML, EMS posture
IndiaYour own siteMumbai and Delhi PoPsFour Indian citiesEight Indian DCsMumbai and ChennaiPoPs not documented
Best fitOn-site inspectionProxySG renewalsDeepest cloud proxyApp-instance controlCheap DNS everywhereFortiGate, gone remote
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose FortiProxy if…

  • ✓Web traffic must be decrypted and inspected on your own premises, with logs on servers you control
  • ✓You want proxy, web filtering, DNS filtering and inline CASB under one policy on one appliance or VM
  • ✓You are replacing an older on-premises proxy and need explicit mode, PAC files, WCCP and ICAP to carry over

Compare alternatives if…

  • ✓Most of your users work off the network — FortiSASE, Zscaler, Netskope and Umbrella all ship roaming agents
  • ✓You need API scanning of data already in SaaS apps — Netskope and Zscaler document both CASB modes
  • ✓You want a published price — Cisco Umbrella’s tiers and the reported Zscaler range are easier to budget

Do not expect…

  • ✓A roaming agent, or Fortinet-hosted Indian PoPs — the proxy is wherever you place it
  • ✓API-based CASB, or a public list price
  • ✓A FortiProxy analyst placement — Gartner’s 2025 SSE Challenger rating is for FortiSASE

Fortinet FortiProxy is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does unfiltered web traffic cost you?

Drag the sliders (users behind the proxy; IT staff-hour cost). Estimates model the IT time spent per user each year on web-borne malware clean-ups, block-list upkeep and one-off access exceptions, at an assumed 1.5 hours per user a year, with 70% of it removed by category filtering, inspection and one policy. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual web-threat handling cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Fortinet publishes no FortiProxy price. You buy a 400G, 2000G or 4000G appliance or a yearly VM subscription, then the required SWG Protection Bundle — web, video and DNS filtering, application control, antivirus, IPS, botnet blocking and cloud sandboxing — sold as a yearly subscription in 500-user seat lots that can be shared across your devices. Data Protection (DLP with OCR), client browser isolation and extra VDOMs are optional licences. Without the bundle the box only caches and optimises WAN traffic. TechBag sizes your sites first, then quotes in INR with GST.

Device + SWG Protection Bundle

Best for web, DNS and threat filtering on site

  • Appliance or yearly VM subscription
  • Required bundle in 500-user seat lots
  • Web, DNS, app control, AV, IPS, sandbox

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Optional licences

Best for data protection and risky browsing

  • Data Protection: DLP with OCR, image AI
  • Client browser isolation on Windows
  • Extra VDOMs for business units

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Sizing

How many users sit behind each site? Map them to the 400G, 2000G, 4000G or a VM using Fortinet’s user ratings.

2
Certificates

Can you push the inspection CA to every managed device, and who owns the bypass list for pinned and banking apps?

3
Deployment mode

Explicit with PAC files, transparent inline, WCCP or policy routing? Which fits your current firewall and cabling?

4
Remote users

How will laptops off the network be filtered — a published proxy, a VPN back home, or FortiSASE alongside?

5
CASB scope

Is inline tenant and activity control enough, or do you also need API scanning of data already stored in SaaS apps?

6
Regulation

Which applies — SEBI CSCRF 4.b, 4.c and 4.e, CERT-In’s 180-day logs, or government proxy-only internet rules?

7
Patching

Will you run 7.6.6 or later, keep the admin interface off the internet, and leave FortiCloud SSO off unless needed?

8
Licence

Does the quote list the device, SWG bundle seat lots, Data Protection, isolation, VDOMs and support term in INR with GST?

FAQ

Questions buyers ask

FortiProxy is Fortinet’s on-premises secure web gateway, sold as a 400G, 2000G or 4000G appliance or as a VM. It runs as an explicit or transparent proxy and applies FortiGuard web, video and DNS filtering, TLS inspection, application control, inline CASB, antivirus and IPS to your users’ web traffic.

Ready to evaluate Fortinet FortiProxy?

Count your users per site and plan the inspection certificate first, or let a TechBag advisor size the appliance, draft the bypass list and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.