Fortinet white logo
Fortinet white logo

CLI Reference

config wanopt settings

config wanopt settings

Configure WAN optimization settings.

config wanopt settings
    Description: Configure WAN optimization settings.
    set host-id {string}
    set tunnel-ssl-algorithm [high|medium|...]
    set auto-detect-algorithm [simple|diff-req-resp]
end

config wanopt settings

Parameter

Description

Type

Size

host-id

Local host ID (must also be entered in the remote FortiProxy's peer list).

string

Maximum length: 35

tunnel-ssl-algorithm

Relative strength of encryption algorithms accepted during tunnel negotiation.

option

-

Option

Description

high

High encryption. Allow only AES and ChaCha.

medium

Medium encryption. Allow AES, ChaCha, 3DES, and RC4.

low

Low encryption. Allow AES, ChaCha, 3DES, RC4, and DES.

auto-detect-algorithm

Auto detection algorithms used in tunnel negotiations.

option

-

Option

Description

simple

Use the same TCP option value in SYN/SYNACK packets. Backward compatible.

diff-req-resp

Use different TCP option values in SYN/SYNACK packets to avoid false positive detection.

config wanopt settings

config wanopt settings

Configure WAN optimization settings.

config wanopt settings
    Description: Configure WAN optimization settings.
    set host-id {string}
    set tunnel-ssl-algorithm [high|medium|...]
    set auto-detect-algorithm [simple|diff-req-resp]
end

config wanopt settings

Parameter

Description

Type

Size

host-id

Local host ID (must also be entered in the remote FortiProxy's peer list).

string

Maximum length: 35

tunnel-ssl-algorithm

Relative strength of encryption algorithms accepted during tunnel negotiation.

option

-

Option

Description

high

High encryption. Allow only AES and ChaCha.

medium

Medium encryption. Allow AES, ChaCha, 3DES, and RC4.

low

Low encryption. Allow AES, ChaCha, 3DES, RC4, and DES.

auto-detect-algorithm

Auto detection algorithms used in tunnel negotiations.

option

-

Option

Description

simple

Use the same TCP option value in SYN/SYNACK packets. Backward compatible.

diff-req-resp

Use different TCP option values in SYN/SYNACK packets to avoid false positive detection.