Yes, I have tested this on 5.6.11 and 6.2.3 FortiOS version, I tested with FGT-60E, the WSA was running 11.7 and 11.8 AsyncOS.
The setup which worked me is shown in the image below.
Traffic flow:User Client -> [internal6]FGT[DMZ] -> WSA -> [DMZ]FGT[WAN]-> Internet -> [WAN]FGT[DMZ] -> WSA -> [DMZ]FGT[internal6] -> User/client
It is worth mentioning that this only worked for me, when the WSA used the FGT (WCCP_Router) as the gateway to reach the internet!
For eg: The WSA uses 10.10.10.1 as WCCP_Router, then the WSA must be configured to use 10.10.10.1 as default gateway too.
I used the service ID 0, 70 on WSA as well as on the FGT. 0 for HTTP & 70 for HTTPs.
forward-method was GRE, return-method was GRE, assignment-method was HASH. No authentication was configured.
post edited by Prab - 2020/01/30 04:20:09