Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kelv1n
New Contributor

v5.2.3 - WAN Optimization changes

Hi Guys

 

The release notes for 5.2.3 show the following

 

"WAN Optimization feature only available on FGT models with two disks"

 

Can anybody confirm the impact of this, we have 200D's and I'd like to know if this means they've suddenly pull WAN optimisation support for them. AFAIK they only ship with a single 64GB drive.

7 REPLIES 7
Carl_Wallmark
Valued Contributor

Yes it´s at least gone from the GUI, however I can still see the "wanopt" menu in CLI.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
kelv1n

Thanks for confirming.

 

Won't affect us too much, but I'd be very p***ed off customer if it was a key feature for us (especially after just spending £20k on buying several HA pairs).

Carl_Wallmark
Valued Contributor

mm, wanopt has been an ongoing issue since it was released, best thing would be to remove it completely because you can never rely on it since you never know how long it will be available before they remove it AGAIN....

 

But I dont think they will..... I think it´s a marketing feature more than a real working feature. Does anyone even use it ?

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Carl_Wallmark
Valued Contributor

I updated a FG-100D which contains a disk with 16GB and apperantly it contains a 16GB boot flash device, so in this case it´s two disks, and I have the wanop in the GUI, by design or...?

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
ejhardin
Contributor

WAN OPT is still available on my 60C after upgrading. Will try a fresh install this weekend. 

FortiRack_Eric
New Contributor III

I strongly advise against wan-opt on a FG60C (or D) for that fact.

Even if it works, the gain is minimal on a 60C and the risk of damaging your SD disk is enormous.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
SteveRoadWarrior
New Contributor III

Three tales of WANOPT for your amusement:

 

1. WANOPT was preventing AD from Syncing but only under certain situations

after the AD server eventually got too far out of sync for the workstations, we took a look at it

it was unable to even re-join the domain after a forceremoval

had to disable WANOPT before this would work again

 

1. Details:

enabled WANOPT between a 60D and 100D

MAPI and port 445 were enabled for WANOPT

charts claimed that we were seeing a reduction in bandwidth

 

2. WANOPT saved our bacon.  An ISP's MPLS circuit had older Cisco gear on it which was not handling TCP Windowing properly.  They were unwilling/unable to adjust this.  Disabling TCP windowing options on newer OS'es didn't seem to fix.

enabled WANOPT for all protocols/ports and it allowed the users to browse the web properly again (well, got them up to 60% of the line (10Mbit) bandwidth, they were getting a spotty 10-15%).  This issue only affected their browsing, site to site TCP was ok.

 

2. Details:

WANOPT (not caching per se, more just the protocol acceleration) enabled between 80C and 60C

enabled for TCP protocol, byte caching off

 

3. WANOPT actually worked for Windows Files.

Used two firewalls to wan accelerate the windows file sharing between two sites.  on the bench, it took a while before I could prove the results that the FG Monitor charts were claiming.  It's worth noting that the actual results were much less than the charts claimed, but still worth using the feature.

Got the best results with SMB 1.x sessions and it only seemed to really help when you pulled the same file several times.  After you downloaded the same file 2-3 times, the next time you got a copy the session would go much faster for at least a third of the download.  The more times you retrieved the file, the more reliable the system worked.

Any time I used SMB 2.x or 3.x the system didn't help even through it claimed to.  I was monitoring the WAN bandwidth and file download speed so I knew that the chart claims were wrong.

 

Labels
Top Kudoed Authors