Secure tunnelling
WAN optimization and web caching
FortiGate Version 4.0 Administration Guide
630
01-400-89802-20090424
3
If required, move the rule to a different position in the list.
The HTTPS rule can be above or below the HTTP rule.
“Moving a rule to a different position in the rule list” on page 607
.
4
Add a SSL server to offload SSL encryption and decryption for the web server.
5
Go to
System > Certificates > Local Certificates
and select
Import
to import the web
server’s CA. Set the name of the local certificate to Rev_Proxy_Cert_1.
The certificate key size must be 1024 or 2048 bits. 4096-bit keys are not supported.
6
Connect to the CLI and enter the following command to add the SSL server.
config wanopt ssl-server
edit rev_proxy_server
set ip 172.10.20.30
set port 443
set ssl-cert Rev_Proxy_Cert_1
end
Configure other
ssl-server
settings as required for your configuration.
Secure tunnelling
Select
Enable Secure Tunnel
in WAN optimization rules to use SSL to encrypt the traffic in
the WAN optimization tunnel. The FortiGate units use FortiASIC acceleration to accelerate
SSL decryption and encryption of the secure tunnel. The secure tunnel uses the same
TCP port as a non-secure tunnel (TCP port 7810).
You must configure and add an authentication group to the WAN optimization rule to use
secure tunneling. The authentication group configures the certificate or pre-shared key
parameters required by the secure tunnel. The WAN optimization rules at both ends of the
tunnel should have compatible authentication group configurations. For example, they
should have the same certificates or the same pre-shared key.
WAN optimization over IPSec VPN
Another way to encrypt WAN optimization traffic is to configure a route-based IPSec VPN
between the client and server FortiGate units. Then configure WAN optimization to use
the IPSec interfaces on the FortiGate units for the WAN optimization tunnel. No special
configuration is required except making sure the routing configuration sends the WAN
optimization packets through the IPSec interfaces.
WAN optimization with FortiClient
FortiClient 4.0 WAN optimization can work together with WAN optimization on a FortiGate
unit to accelerate network access. FortiClient will automatically detect if WAN optimization
is enabled on the optimizing FortiGate unit it is connected to and transparently make use
of the byte caching and protocol optimization features available.
To enable FortiClient WAN Optimization from FortiClient
1
Go to
Status > WAN Optimization
.
2
Select
Enable WAN Optimization
.
3
Enable the protocols to be optimized:
HTTP
(web browsing),
CIFS
(Windows file
sharing),
MAPI
(Microsoft Exchange) and
FTP
(file transfers).
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...