Fortinet black logo

Technical Note: How to improve Explicit Proxy performances on FortiGate

FD39695

5.2.5
Copy Link
Copy Doc ID 2600140f-48e6-11ea-9384-00505692583a:24
Technical Note: How to improve Explicit Proxy performances on FortiGate
Products
FortiGate
FortiGate v5.2
Description
On FortiGate the WAD daemon is used to perform explicit proxy tasks.

With release 5.0, FortiGate is limited to a single WAD process regardless of the number of available CPUs.

With release 5.2, the limitation was removed and multiple WAD processes can be used in parallel. The number of WAD process that can run in parallel depends on hardware and configuration.

Examples:

FortiGate 3600C: between 1 and 32 WAD process, default 16.
FortiGate 500D: between 1 and 4 WAD process, default 2.
FortiGate 100D: between 1 and 4 WAD process, default 2.
Solution
To improve Explicit Proxy performance on FortiGate:

1) Upgrade to release 5.2 (last patch) or above.

2) Increase the number of WAD processes that can be used in parallel with the commands:
config global
config system global
set wad-worker-count x
end
Finding the best number of WAD workers to use for a device is not easy. The balance must be found between resources used for WAD and for other processes. It might require lots of testing with different combinations to find the correct balance.
Previous
Next
Technical Note: How to improve Explicit Proxy performances on FortiGate
Products
FortiGate
FortiGate v5.2
Description
On FortiGate the WAD daemon is used to perform explicit proxy tasks.

With release 5.0, FortiGate is limited to a single WAD process regardless of the number of available CPUs.

With release 5.2, the limitation was removed and multiple WAD processes can be used in parallel. The number of WAD process that can run in parallel depends on hardware and configuration.

Examples:

FortiGate 3600C: between 1 and 32 WAD process, default 16.
FortiGate 500D: between 1 and 4 WAD process, default 2.
FortiGate 100D: between 1 and 4 WAD process, default 2.
Solution
To improve Explicit Proxy performance on FortiGate:

1) Upgrade to release 5.2 (last patch) or above.

2) Increase the number of WAD processes that can be used in parallel with the commands:
config global
config system global
set wad-worker-count x
end
Finding the best number of WAD workers to use for a device is not easy. The balance must be found between resources used for WAD and for other processes. It might require lots of testing with different combinations to find the correct balance.
Previous
Next