Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
veechee
New Contributor

Share your WAN Optimization experiences here

So I finally took the time to try WAN Optimization between two FortiGate' s. Both are 60C' s with 32 GB Class 10 SD cards installed, and 29 GB provisioned for WAN Optimization storage space. There are Windows servers at each site with SMB file shares. I did a rule set on each site to cache traffic requested by client PCs to the servers on each side. I made two rules: one for port 445, which I think was enough, but just in case I also made one for 49152-65535, which is the random port range Server 2008/Vista+ use in conjunction with port 445. The results were fairly immediate and somewhat impressive. Downloading a 30 MB file will take 10 mins the first time, and only ~1 minute the second time - peaking at 2 MB/s file transfer versus maybe 40 KB/s for a non-cached file. However, I do notice increased latency versus before, so I' m reluctant to roll out optimization to the server to server traffic (the servers seem to use 445 for a lot of communication) and to traffic outside of CIFS/SMB. I do think this has great potential but the Fortinet docs and knowledge base are lacking on examples for site-to-site traffic optimization (e.g., generic TCP optimization mentioned in the " Inside FortiOS" sheet but totally absent in any examples). If people are interested in my rule sets that I got to work I' d be happy to share them, and conversely I' d love to hear from others that have deployed WAN Optimization and where it is benefiting them.
20 REPLIES 20
Maik
New Contributor II

Hi veechee I did my wanopt test last year and expected more benefits than i really got. I also noticed the " added delays" . what network latency do you have between your two sites? could you please try the following for me? 1) create an office document (word, excel etc) of any size (e.g.1mb) 2) transfer it twice from local to the remote site -> do you see the caching effect? 3) then on the local site, open the office document and close it again (notice, no " save" was done). 4) transfer it again -> do you still see the caching effect? thanks
emnoc
Esteemed Contributor III

Has anybody seen WAN-opt bake-offs between the other players just how well does fortinet stack up to cisco, riverbed, sliverpeak,etc....? I' ve personally have not tried any wan-opt outside of the lab, but have use the others mention above. And all has some benefits over fortinet in their approach, methods, reporting, statistics gathering and overall performance & bandwidth savings.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kinderu28
New Contributor

Hi guys, I' m new on this forum so please be gentle. I' m doing my thesis on wan optimization using Fortinet equipments(Fortigate 51B, version 4.0 MR2). I' ve managed to see how traffic has been optimized (according to the reduction rate graph in the monitor menu) for all protocols,except 1.MAPI. TCP,CIFS,FTP,HTTP have been successfully optimized by the equipment except for the MAPI protocol.After 3 days trying to deploy Exchange server(AD,DNS,Outlook) i finally got some MAPI traffic by sending emails(with or without attachments).I' ve managed to send across the link about 30-50MB of MAPI traffic, but there was no wan optimization.Reduction rate 0%. My test consisted on sending a mail with an attachment and then basically downloading the same attachment several times via Outlook.I' ve used transparent mode and byte caching int the wan rule for the MAPI protocol and used a peer to peer configuration .In my opinion this should' ve resulted in some kind of reduction. Have any of you managed to obtain any reduction for the MAPI protocol?Some feedback or any kind information regarding this aspect would be very useful. Thanks a lot
simonorch
Contributor

Same here, i' ve got MAPI hitting the wan opt rule but i' m not getting any reduction.
veechee
New Contributor

Re: MAPI In Outlook 2007 and 2010 the option exists to encrypt traffic between the Exchange server and the client. Is that enabled? This is just a guess, but I think that the encryption would remove the ability for the Fortigate to optimize any traffic. kinderu28: What are you experiences with latency when using WAN Optimization on all those protocols?
Maik
New Contributor II

before you invest to much time in WanOpt & MAPI, I recommend to open a support ticket and wait for their response
kinderu28
New Contributor

I' m using Exchange 2003 and Outlook 2003. @veechee: I haven' t quite used o monitoring tool for measuring latency(haven' t found one yet:) ),although i noticed that http performs quite well if data is cached.It' s a lot faster when downloading a file that was previously cached.However FTP and CIFS don' t seem that faster,but i have to make more tests like: - 10.000 files of 100 Kbytes - 10 files of 100Mbytes - 1 file of 1Gbyte I will get back to you shortly(1 or 2 day max) PS:i achieved 98%reduction rate for TCP traffic using jperf. PS2:i notice that memory usage is quite high(50-60%) and sometimes sends the unit into conserve mode. PS3:My 2 FortiGates are directly connected via the wan1 interface.I was thinking of creating a routing loop between (3-4 hops) to really simulate a WAN environment
kinderu28
New Contributor

@Maik: for some reason i can' t open a ticket or submit my product. Actually,it is not my product, it belongs to my University, and it could be for teaching/testing purpose only.I don' t know.Both 51-B have the same serial number:FG50BH3G0*******.I' m not sure if i can give away this information,that' s why i haven' t given the full serial.
veechee
New Contributor

kinderu28, Based solely on my personal observations, WAN Optimization on CIFS and the generic TCP optimization, increases the latency, so for example, pulling up a folder is slower, but once I initiate a file transfer if it' s cached it goes faster overall. I' d definitely recommend you try to simulate slower speed links AND latency, as these bare the things WAN Optimization is supposed to help overcome, and they do not exist in a direct connection situation.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors