Fortigate )raffic *ptimi+ation

March 24th, 2012 Daniel

Fortigate is capable of Traffic Optimization, isnt that cool ? The follo ing are the things that can affect the !et or" an# $pplication %erformance 1& 'an# i#th 2& (atenc) *& Thro+ghp+t 4& ,ongestion -& %ac"et (oss

The Fortinet Firewa l is capable of #ealing ith all of them b) +sing .$! Optimization Techni/+e0 1& %rotocol Optimization 2& ')te ,aching *& .eb ,aching 4& Transparent pro1)

,. -rotoco *ptimi+ation
2ts an application techni/+e to impro3e performance of 4TT%, ,2F5, FT%, M$%2 an# T,% protocol traffic& 2 g+ess )o+ "no all of them e1cept ,2F5& This is a common internet file s)stem protocol 6 pro3i#es file access, recoring, change notification etc

2. .yte Caching
The Fortigate Fire all can brea" large +nts of application #ata into small ch+n"s of #ata, labeling each ith a hash, an# stores the ch+n"s an# has in a #ictionar) file& 2t assigns to"en to it an# the it sen#s the #ictionar) to the other Fortigates&

2f ch+n"s an# hash are recognize# it sen#s the to"en 7the #ictionar) m+st be the same on both of the si#es8&

/. (eb Caching
This techni/+e is also "no n as 4TT% pro1)ing& 2t stores the 4T(M pages, images an# more on the local 4DD& There are * mo#es of .eb caching0 a& !on9transparent for ar# pro1) caching b& Transparent for ar# pro1) caching 6 if )o+ +se this, please "eep in min# that the Fortigate m+st be place# near the net or" gate a)s c& Transparent re3erse pro1) caching 6 this is a metho# to re#+ce the loa# on a b+s) ser3er an# the 2nternet& eb ser3er b) +sing a eb cache ser3er bet een the

0. )ransparent pro#y
The +sers are not are of the Fortigate& The clients comm+nicate to the ser3er the same a) as optimization is compatible ith 2#entif)9'ase# fire all policies also itho+t the .$! optimization: the .$!

;eep in min# that all the fire all policies are applie# before the .$! optimization policies<r+les are applie#& 5o if )o+ bloc" the traffic, it not get optimize# of co+rse


)here 2 types of (A$ optimi+ation ru es: 1& $cti3e9%assi3e Mo#e 2& %eer9to9peer Mo#e

,. Acti&e -assi&e 1o'e The Fortigat Fire all on both en#s of the .$! optimization t+nnel operate in a "in# of client ser3er config+ration& The sessions are originate# on the client Fortigate an# are terminate# on the passi3e Fortigate fire all& The remote peer +ses a+to9#etection thro+gh T,% option as a #isco3er) mechanism to locate an) peers on the path to the ser3er& 2. -eer-to--eer 1o'e 2n this mo#e, both peers ha3e peer lists that incl+#es names an# 2% a##resses of the Fortigate #e3ices& 'oth Fortinet fire alls sho+l# ha3e matching r+les&

Genera H2$)! about Fortigate Firewa (A$ *ptimi+ation

1& ;eep in min# that %eer9to9%eer .$! optimization t+nnels +se port =>10& 5o if )o+ ha3e another fire all in front, #o not forget to O%?! that port& 2& Onl) one protocol can be selecte# in a .$! optimization r+le& 5o )o+ ha3e one r+le for each protocol& ?1ample0 @+le 1 for 4TT% traffic& *& Fire all traffic shaping 7A+alit) of 5er3ice8 is compatible onl) the optimization techni/+es are ignore#& ith client<ser3er7acti3e9passi3e8 transparent mo#e& For rest of the mo#es,

4& Of the fire all polic) incl+#es a threa# management profile, the pac"et is processe# b) the profile an# not b) .$! optimization& To appl) .$! optimization to traffic that is accepte# b) a fire all polic) containing a threa# management profile, m+ltiple fire all +nits or m+ltiple Fortigate 34*1 ('oms/) m+st be +se#: to #o this )o+ m+st appl) the the threa# management profile in the first FB +nit or CDOM an# appl) .$! optimization in the secon# Fortigate +nit or 34*1 ('oms/)& -& 55( is also capable of being optimize# b) +sing the .eb ,aching optimization techni/+es& The Fortinet fire all caches 4TT%s D& Fortigate is also capable of .,,% 6 .eb ,ache ,omm+nication %rotocol& Eo+ can chec" this article abo+t Fortigate .,,%& eb pages&

Posted in Fortigate, Fortinet Tags: fortigate optimization, fortigate wan optimization, fortinet firewall optimization, fortinet wan optimization, wan optimization fortigate

