Configuring a WAN optimization rule WAN optimization and web caching
FortiGate Version 4.0 Administration Guide
608 01-400-89802-20090424
http://docs.fortinet.com/ • Feedback
Configuring a WAN optimization rule
This section describes the WAN optimization rule options. The options that appear in
WAN optimization rules change depending on how you configure the rule. This section
describes all of the options. To add a WAN optimization rule, got to WAN Opt. & Cache >
Rule and select Create New.
See the following sections for information about the configuring WAN optimization rules
for different types of WAN optimization configurations.
• “Configuring web cache only WAN optimization” on page 611
• “Configuring client/server (active-passive) web caching” on page 612
• “Configuring peer to peer web caching” on page 614
• “Configuring client/server (active-passive) WAN optimization” on page 617
• “Configuring peer to peer WAN optimization” on page 620
To add a WAN optimization rule, go to WAN Opt. & Cache > Rule and select Create New.
Mode Select Full Optimization to add a rule that can apply all WAN optimization features.
Select Web Cache Only to add a rule that just applies web caching. If you select
Web Cache Only you can configure the source and destination address and port to
the rule. You can also select Transparent Mode and Enable SSL.
Source Enter an IP address, followed by a forward slash (/), then subnet mask, or enter an
IP address range separated by a hyphen. See “About WAN optimization
addresses” on page 622.
Only packets whose source address header contains an IP address matching this
IP address or address range will be accepted by and subject to this rule.
For a passive rule, the server (passive) source address range should be
compatible with the source addresses of the matching client (active) rule. To match
one passive rule with many active rules the passive rule source address range
should include the source addresses of all of the active rules.
Destination Enter an IP address, followed by a forward slash (/), then subnet mask, or enter an
IP address range separated by a hyphen. See “About WAN optimization
addresses” on page 622.
Only packets whose destination address header contains an IP address matching
this IP address or address range will be accepted by and subject to this rule.
For a web-cache only rule, if you set you set Destination to 0.0.0.0 the rule caches
web pages on the Internet or any network.
For a passive rule, the server (passive) destination address range should be
compatible with the destination addresses of the matching client (active) rule. To
match one passive rule with many active rules the passive rule destination address
range should include the destination addresses of all of the active rules.
Port Enter a single port number or port number range. Only packets whose destination
port number matches this port number or port number range will be accepted by
and subject to this rule.
For a passive rule the server (passive) port range should be the same or a subset
of the matching client (active) rule port range.
For a passive rule, the server (passive) port range should be compatible with the
port range of the matching client (active) rule. To match one passive rule with many
active rules the passive rule port range should include the port ranges of all of the
active rules.