Cisco Wide Area Virtualization Engine 274 Troubleshooting Guide Page 51

  • Download
  • Add to my manuals
  • Print
  • Page
    / 594
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 50
1-7
Cisco Wide Area Application Services Configuration Guide
OL-26579-01
Chapter 1 Planning Your WAAS Network
Site and Network Planning
Some organizations close port 139 on their networks to minimize security risks associated with this port.
If your organization has closed port 139 for security reasons, you can configure your WAAS network to
bypass port 139. If this is the case in your organization, you need to perform the following task to bypass
port 139 and use port 445 in its place if you have only deployed the CIFS services in your WAAS
network:
Enable WCCP Version 2 on your routers and branch WAE, as described in the Cisco Wide Area
Application Services Quick Configuration Guide. Alternatively, you can use inline mode on a branch
WAE with a Cisco WAE Inline Network Adapter or Cisco Interface Module installed.
Ports 88 and 464
If you are using Windows Domain authentication with Kerberos enabled, the WAE uses ports 88 and 464
to authenticate clients with the domain controller.
Firewalls and Directed Mode
By default, WAAS transparently sets up new TCP connections to peer WAEs, which can cause firewall
traversal issues when a WAAS device tries to optimize the traffic. If a WAE device is behind a firewall
that prevents traffic optimization, you can use the directed mode of communicating to a peer WAE. In
directed mode, all TCP traffic that is sent to a peer WAE is encapsulated in UDP, which allows a firewall
to either bypass the traffic or inspect the traffic (by adding a UDP inspection rule).
Any firewall between two WAE peers must be configured to pass UDP traffic on port 4050, or whatever
custom port is configured for directed mode if a port other than the default is used.
If a WAE using directed mode is behind a NAT device, you must configure the NATed IP address on the
WA E.
For more information about configuring directed mode, see the “Configuring Directed Mode” section on
page 1-27.
Firewalls and Standby Central Managers
Primary and standby Central Managers communicate on port 8443. If your network includes a firewall
between primary and standby Central Managers, you must configure the firewall to allow traffic on port
8443 so that the Central Managers can communicate and stay synchronized.
Performance Tuning for High WAN Bandwidth Branch Offices
WAAS combines Layer-4 TCP optimizations with Layer-7 application accelerators for various protocols
including CIFS. For some branch offices with high WAN bandwidth (for example, above 50 Mbps), if
the native latency is low (for example, below 20 ms RTT), depending on the number of user sessions and
data patterns, applying Layer-4 optimizations alone may provide optimal levels of performance. In such
cases, we recommend measuring end-user response times under production load to determine the
appropriate operational state for the application accelerators and sizing.
Page view 50
1 ... 50 51 52 ... 594

Comments to this Manuals

No comments