Created on
10-26-2021
08:07 AM
Edited on
10-21-2025
01:22 AM
By
Jean-Philippe_P
Description
This article describes how to perform the WAD source affinity exemption for a specific source address.
Scope
FortiGate.
Solution
Note 1: These commands are valid for FortiProxy. Tested and verified on the LAB.
Note 2: Running 'show full web-proxy global' keeps the commands 'set src-affinity-exempt-addr' and 'set src-affinity-exempt-addr6' invisible, and it may be considered as a non-existing command.
FPX # sh full web-proxy global
config web-proxy global
set ssl-cert "default-server-cert"
set ssl-ca-cert "default-ca"
set fast-policy-match enable
set ldap-user-cache enable
set proxy-fqdn "default.fqdn"
set max-request-length 8
set max-message-length 32
set strict-web-check disable
set forward-proxy-auth disable
set forward-server-affinity-timeout 30
set webproxy-profile ''
set learn-client-ip log-only
unset learn-client-ip-from-header
set strict-guest disable
set https-replacement-message enable
set message-upon-server-error enable
set trace-auth-no-rsp disable
set policy-category-deep-inspect enable
set log-policy-pending disable
set extended-log disable
set log-http-transaction disable
set log-app-id disable
set realm "default"
end
To activate these commands, it is important to first configure the commands 'set learn-client-ip-from-header' and 'set learn-client-ip-srcaddr <all>'. After activating them, the commands 'set src-affinity-exempt-addr <X.X.X.X>' and 'set src-affinity-exempt-addr6 <Y.Y.Y.Y>' are visible:
FPX # sh full web-proxy global
config web-proxy global
set ssl-cert "default-server-cert"
set ssl-ca-cert "default-ca"
set fast-policy-match enable
set ldap-user-cache enable
set proxy-fqdn "default.fqdn"
set max-request-length 8
set max-message-length 32
set strict-web-check disable
set forward-proxy-auth disable
set forward-server-affinity-timeout 30
set webproxy-profile ''
set learn-client-ip log-only
set learn-client-ip-from-header x-forwarded-for
set learn-client-ip-srcaddr "all"
set strict-guest disable
set https-replacement-message enable
set message-upon-server-error enable
set trace-auth-no-rsp disable
set policy-category-deep-inspect enable
set log-policy-pending disable
set extended-log disable
set log-http-transaction disable
set log-app-id disable
set realm "default"
end
FPX # config web-proxy global
FPX (global) # set src-affinity-exempt-addr
src-affinity-exempt-addr IPv4 source addresses to exempt proxy affinity.
src-affinity-exempt-addr6 IPv6 source addresses to exempt proxy affinity.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.