



More than 90 per cent of malware now communicates over encrypted channels. For Indian enterprise security teams, that statistic is not an abstraction—it is a daily operational problem. When attackers wrap their command-and-control (C2) traffic, data-exfiltration payloads, and dropper downloads inside TLS, a firewall that only reads packet headers is effectively blind. Deep Packet Inspection (DPI) on a next-generation firewall (NGFW) is the primary surgical instrument that restores that visibility. This post walks through how FortiGate DPI works, why it matters for Indian regulatory compliance, common deployment pitfalls, and how PJ Networks and the PrahiX Ora platform deliver it as a managed, always-on capability.
The shift toward encrypted malware is driven by simple attacker economics. TLS certificates are free. Most enterprise inspection points—legacy firewalls, basic IDS sensors, even many cloud gateways—cannot or do not decrypt and re-inspect traffic. Attackers know this and exploit the blind spot systematically.
In the Indian context, several threat patterns have become routine:
Without SSL/TLS inspection, your firewall sees only the TLS handshake metadata—SNI hostname and certificate issuer—not the payload. Deep Packet Inspection restores full payload visibility by acting as a transparent TLS proxy inside the network perimeter.
FortiGate’s DPI engine operates at multiple layers simultaneously. Understanding those layers is essential for any architect planning a deployment.
FortiGate intercepts outbound TLS sessions in one of two modes:
For inbound inspection (protecting published applications), FortiGate supports deep inspection on reverse-proxy flows, enabling the WAF and IPS engines to inspect encrypted traffic destined for internal web servers.
FortiGate’s Application Control engine uses a combination of protocol decoders, behavioral heuristics, and FortiGuard’s threat-intelligence feed to identify applications even when they use non-standard ports or attempt to masquerade as HTTPS. This is how the platform distinguishes legitimate Microsoft Teams traffic from a threat actor using a Teams-look-alike C2 framework.
Once TLS is terminated, the IPS engine evaluates each decrypted stream against a signature library that Fortinet updates multiple times per day via FortiGuard. Signatures cover exploit kits, vulnerability-specific shellcode patterns, and behavioral indicators like beaconing cadence and encoded command-strings typical of known RAT families.
For files and attachments traversing the firewall—PDFs, Office documents, executables—FortiGate can forward samples to FortiSandbox (on-premises or FortiCloud) for dynamic detonation. The sandbox executes the sample in an isolated VM, observes runtime behavior, and returns a verdict. Only clean files proceed; suspicious ones are quarantined and an alert is raised.
DPI deployments are not plug-and-play. Several India-specific factors shape the architecture:
Full SSL inspection requires endpoints to trust the FortiGate’s CA certificate. In large Indian enterprises—especially those running mixed Windows/Linux/mobile fleets across multiple offices—this rollout must be coordinated through Active Directory GPO, Intune, or mobile device management. Failures here cause browser certificate errors that users interpret as “the internet is broken,” generating support tickets and pressure to disable inspection.
Best practice: Stage the rollout department by department. Start with IT and security teams, validate, then expand. Use FortiGate’s SSL exemption list to exclude known-problematic destinations (banking applications that use certificate pinning, government portals with self-signed certificates) rather than disabling inspection globally.
DPI is CPU and memory intensive. A FortiGate sized for 10 Gbps firewall throughput may deliver 2–3 Gbps under full SSL inspection load. Indian organisations running multi-gigabit internet uplinks must size hardware with DPI-specific throughput figures from the FortiGate datasheet, not the headline firewall throughput. FortiGate models with dedicated NP (Network Processor) and CP (Content Processor) ASICs offload much of this work from the main CPU.
Under the Digital Personal Data Protection (DPDP) Act 2023, intercepting and logging personal data—including email content flowing over TLS—carries compliance obligations. Organisations should:
Mobile applications and some enterprise software pin their server certificates, meaning they will reject a FortiGate re-signed certificate and fail to connect. The correct response is to add these destinations to the SSL exemption list—not to disable DPI globally. Common pinned destinations include corporate MDM agents, some banking apps, and selected Google services.
Deploying FortiGate DPI generates a significant volume of security events—IPS triggers, malware detections, anomalous application usage, and SSL handshake anomalies. Without a platform to ingest, correlate, and prioritise those events, alert fatigue sets in and genuine threats are buried in noise. This is the operational gap that the PrahiX Ora unified SecOps platform addresses—a platform we deploy and operate for clients as PJ Networks’ primary field operations partner for PrahiX Tech Pvt Ltd.
Ora’s SIEM module ingests FortiGate logs alongside events from endpoints, Active Directory, cloud workloads, and SaaS platforms. Correlation rules mapped to MITRE ATT&CK tactics—such as detecting a TLS DPI alert followed by an unusual outbound DNS query from the same host within minutes—are surfaced as a single graph-based attack storyline rather than isolated log lines. This is precisely the kind of multi-source correlation that helps analysts meet CERT-In’s 6-hour incident reporting window: the storyline is already built by the time the analyst opens the ticket.
Tiered retention (hot, warm, and archive storage) supports CERT-In’s direction on 180-day in-country log retention without requiring organisations to budget for hot-storage at full volume for all six months.
Indian enterprise estates are typically multi-vendor—FortiGate firewalls alongside Cisco or Juniper switches, Aruba or Ruckus wireless, and mixed WAN/SD-WAN links from multiple ISPs. Ora’s Network Management System module delivers unified observability across this entire estate using LLDP/CDP topology discovery and ML-based anomaly detection. When a DPI-triggered block causes an application path to fail, the NMS correlates the firewall event with network path telemetry, giving the NOC team an immediate causal chain rather than separate console silos.
For manufacturing, retail, and multi-site Indian enterprises, physical and network security increasingly need to be viewed together. Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras alongside network devices, supporting video analytics for perimeter events. When a physical-access anomaly coincides with a network DPI alert—for example, an after-hours physical entry followed by an encrypted lateral-movement attempt—the combined view in a single operations console dramatically shortens investigation time. This is particularly relevant for facilities covered under DPDP Act data-localisation requirements where physical and logical access to personal data must be jointly audited.
Meeting CERT-In’s mandatory 6-hour reporting requirement for cybersecurity incidents is operationally demanding without automation. Ora’s SOAR module provides pre-built playbook connectors that push blocklists directly to FortiGate the moment a confirmed threat indicator is identified—no human clipboard needed between the SIEM alert and the firewall enforcement point. A typical automated response sequence: DPI detects C2 beacon → Ora SIEM correlates with EDR telemetry → SOAR playbook queries threat-intel feed → confirmed malicious IP is pushed to FortiGate blocklist and the endpoint is quarantined from NAC → incident ticket is auto-drafted with evidence for the CERT-In report. Automation is what makes a 6-hour window realistic at enterprise scale.
In our managed deployments, we consistently encounter the same set of misconfigurations that leave enterprises believing they have DPI coverage when significant gaps remain:
Use this checklist when planning or auditing a FortiGate DPI deployment:
PJ Networks designs, deploys, and operates FortiGate NGFW environments for Indian enterprises as part of our managed security services portfolio. Our standard DPI engagement includes:
If your organisation is running FortiGate firewalls without full SSL inspection enabled, or if DPI alerts are flowing into a console that no one actively monitors, you are carrying more risk than your firewall investment should allow. Speak with our team to assess your current DPI coverage and close the gaps before the next encrypted threat reaches your critical systems.