



When a 400-person manufacturing company in Pune discovered that their firewall had been logging encrypted traffic for six months without inspecting a single byte of it, the CISO’s reaction was disbelief. Their FortiGate was licensed, updated, and running — but Deep Packet Inspection (DPI) had never been switched on. Within those six months, an attacker had quietly exfiltrated engineering drawings through an HTTPS channel the firewall simply waved through. It is one of the most expensive misconfigurations in enterprise security — and it is far more common in India than most IT teams realise.
This guide explains what Deep Packet Inspection is, why it matters specifically for Indian enterprises in 2025, how to configure it on FortiGate correctly, and the operational traps to avoid. If your organisation runs FortiGate as its perimeter or branch firewall — whether managed in-house or through an MSSP — read this before your next quarterly security review.
A traditional stateful firewall inspects the header of a network packet — source IP, destination IP, port, and protocol — and decides whether to allow or block it based on rules. It does not look inside the packet. Deep Packet Inspection goes further: it reads the payload, reconstructs the application-layer stream, and applies security policies to the actual content.
For FortiGate, DPI is the engine behind several critical security features:
Without DPI enabled, all of these capabilities are either disabled or severely limited. You are running an expensive next-generation firewall as a basic packet filter.
Three converging pressures make DPI non-negotiable for Indian enterprises this year.
Over 95% of web traffic is now encrypted with TLS 1.2 or 1.3. Attackers know this. Command-and-control (C2) infrastructure, ransomware callbacks, and data exfiltration channels are almost universally HTTPS. If your firewall is not decrypting and inspecting that traffic, you are blind to the majority of active threats in your environment. A FortiGate without SSL inspection enabled is, for practical purposes, a firewall with a 95% blindspot.
CERT-In’s 2022 directions — still being actively enforced and refined — require organisations to report certain cybersecurity incidents within six hours of becoming aware of them. You cannot report what you cannot detect. DPI is foundational to the detection layer: it surfaces malware downloads, lateral movement over HTTP, credential harvesting, and C2 traffic that would otherwise be invisible. Organisations without DPI enabled will routinely miss incidents entirely, let alone detect them in time to meet the reporting window.
India’s Digital Personal Data Protection Act places obligations on data fiduciaries to safeguard personal data. DLP policies running on top of FortiGate’s DPI engine can detect when Aadhaar numbers, PAN data, or health records are being transmitted outside the organisation — a direct control that helps evidence compliance with the Act’s security obligations. Without DPI, the DLP engine has nothing to inspect.
FortiGate implements DPI through its Security Profiles framework. Each profile can contain one or more inspection engines. The critical concept is the SSL/TLS Inspection Profile — this is the gateway that actually decrypts encrypted sessions before other engines can see the content.
FortiGate offers two primary inspection modes:
For most Indian enterprise deployments, flow-based is the practical starting point. It provides strong detection coverage with manageable performance overhead and can be tuned over time as your team builds operational familiarity.
Use this checklist as a starting framework. Actual implementation should be tested in a staging environment or phased rollout before production-wide enforcement.
Even organisations that have “turned on” DPI often leave significant gaps. Watch for these:
Enabling DPI on FortiGate generates the visibility — but visibility only creates value when it feeds into an operations function that can act on it. For organisations managing complex, multi-site, or multi-vendor estates, that operations layer is where the real challenge lies. This is the operational problem that the PrahiX Ora platform addresses. PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks deploys and operates it for clients as their primary field deployment and operations partner.
SIEM — from raw logs to attack storylines: FortiGate DPI generates rich telemetry: IPS hits, web filter blocks, application control events, SSL inspection summaries, DLP triggers. PrahiX Ora’s SIEM layer ingests this alongside logs from other sources — endpoint agents, identity platforms, cloud workloads — and applies correlation rules mapped to the MITRE ATT&CK framework. Rather than surfacing isolated alerts, the platform reconstructs graph-based attack storylines so analysts see the full kill chain, not individual data points. The SIEM supports tiered log retention (hot, cold, and archive tiers), which aligns with CERT-In’s 180-day in-country log retention direction — so the audit trail DPI produces is stored in a form you can present to a regulator.
NMS — seeing the network your DPI runs on: DPI policies are only as effective as the network visibility that underpins them. PrahiX Ora’s Network Management System provides unified observability across FortiGate firewalls, switches, access points, and WAN/SD-WAN links. LLDP/CDP topology discovery maps your estate automatically; ML-based anomaly detection flags unexpected traffic patterns at the network layer before application-layer signatures fire. For enterprises with fragmented multi-vendor NOC visibility — a common situation in Indian IT estates that have grown through acquisitions or organic branch expansion — this single-pane view closes the blind spots between security and operations teams.
Video surveillance (VMS) — physical and network security converged: For manufacturing, retail, and multi-site organisations, physical security and network security have historically been managed by different teams with different tools. PrahiX Ora’s video surveillance (VMS) module supports ONVIF, Hikvision, and Dahua camera management with integrated video analytics, bringing it into the same operations view as network and security events. When a DPI alert fires on the network simultaneously with a physical access anomaly at a server room, operators see both in context rather than correlating across two separate systems after the fact.
SOAR — meeting the CERT-In 6-hour window: A DPI alert that surfaces an active intrusion at 2 AM on a Friday sets a clock running. CERT-In’s 6-hour reporting window is unforgiving. PrahiX Ora’s SOAR layer includes pre-built playbooks and connectors — including direct integration with FortiGate — that automate the initial response: pushing blocklists, isolating sessions, quarantining endpoints, and generating the incident timeline needed for regulatory notification. Without this automation, meeting the 6-hour window consistently across all incident types requires a manual effort that most security teams cannot sustain.
For organisations that want the full FortiGate DPI value chain — configured correctly, monitored continuously, and operationally supported around the clock — PJ Networks offers managed deployment and operations of PrahiX Ora alongside our managed FortiGate service. Reach out to discuss what a deployment would look like for your estate.
Deep Packet Inspection is not a premium feature to evaluate in the next budget cycle — it is the baseline that makes every other FortiGate security capability functional. In a threat landscape where attackers default to encrypted channels and Indian regulators are actively enforcing incident reporting and data protection obligations, running a next-generation firewall without DPI enabled is the equivalent of installing a CCTV system with the lens cap on.
The good news is that FortiGate makes DPI achievable — the capabilities are already licensed in most enterprise deployments. What most organisations need is not a new product purchase but a structured enablement project, operational processes to act on what DPI surfaces, and a 24/7 operations function to turn visibility into response.
If your team needs a DPI readiness assessment, help configuring SSL inspection profiles, or a fully managed FortiGate and SOC service, speak with the PJ Networks team. We work with Indian enterprises across manufacturing, BFSI, healthcare, and retail to move from firewall ownership to firewall effectiveness.