WANaccel_WFS
WAN Acceleration > WFS Acceleration
This section describes the entities that are present on the WAN Acceleration > WFS Acceleration page.
Figure 78:25 WAN Acceleration > WFS Acceleration
Enables WFS Acceleration and allows user to choose the IP address to associate with the service. See “” section for details. Configures the SonicWALL WXA series appliance to match the details of the Microsoft Win dows Domain that it will join. See “Domain Details Tab” section for details. Displays performance statistics for the WFS Acceleration service. See “Statistics Tab” section for details. Provides diagnostic tools for the WFS Acceleration service. See “Tools Tab” section for details.Configuration Tab
The Configuration tab allows you to enable the WFS Acceleration service and select a public IP address for the WXA series appliance.
Figure 78:26 WFS Acceleration > Configuration
Enable WFS Acceleration Checkbox Enables (checked) the WFS Acceleration service on the WXA series appliance. Enabled by default. ‘Public’ WFS Acceleration Address Drop-down Sets the address object that represents the IP address that the SonicWALL WXA series appliance will use when connecting to servers and clients.
Note You can verify the WFS Acceleration status on the WAN Acceleration > Status page in the WFS Acceleration Panel. Domain Details Tab
The Domain Details tab allows you to configure the SonicWALL WXA series appliance to match that of the Microsoft Windows Domain it is to join. The SonicWALL WXA series appliance may automatically discover the domain details if the DNS server configured on the SonicWALL NSA/TZ series appliance is a domain controller and the DNS server is correctly configured in the domain.
Note The user interface is different if the domain name is not auto-discovered. This requires you to enter the basic details for a domain in a different table.
If you configured the FQDN at initial setup, the SonicWALL WXA series appliance should auto-discover the corresponding NETBIOS domain.
Note Changing the FQDN or the NETBIOS Domain after joining the Windows domain requires the device to rejoin the domain. Displays the hostname for the SonicWALL WXA series appliance. If an account is cre ated on the domain using the SonicWALL WXA series appliance hostname, the SonicWALL WXA series appliance attempts to join the domain. Click the Edit button to modify the hostname, Figure 78:30
Note Changing the hostname requires the old computer account to be manually deleted from the domain controller. The FQDN of the Kerberos server on the Windows Domain. The port number defaults to 88. This server is typically the domain controller.
To edit the server name, you must first unjoin the domain, and then click the Edit button. The Kerberos Server pop-up window appears, Figure 78:31 . Sets the Lightweight Directory Access Protocol (LDAP) server on the network. The port number defaults to 389. This server is typically the domain controller. (Read-only) Indicates the device has joined the domain. If this option is not check but the other checkboxes are, refer to Troubleshooting WFS Acceleration . Machine Account Exists:
Checkbox (Read-only) Indicates an account matching the hostname of the device is found on the domain. There are three pre-requisites before the SonicWALL WXA series appliance can join the domain:
2. SELF must be delegated to join the domain.
3. The computer account password is set to the authorization code (Auto-joining only with the WXA 2000 and 4000 appliances). When an account is created on the domain using the devices hostname, the device dis covers the domain and should configure itself. Trusted for Delegation:
Checkbox (Read-only) Indicates that the computer account of the SonicWALL WXA series appli ance on the Domain Controller is trusted for delegation. When this checkbox is checked, the computer account IS trusted for delegation.
This is a necessity and requires the administrator to configure the domain controller to confirm that the SonicWALL WXA series appliance can be trusted for delegation. Displays the server that the SonicWALL WXA series appliance will synchronized its clock with. This server is usually the Domain Control because the SonicWALL WXA series appliance must closely match that of the Domain Controller.
Click the Edit button to modify the server, Figure 78:32 . (Read-only) Displays the current primary DNS server IP address, which must be a domain DNS server for WFS Acceleration to function properly. Configures the WFS Acceleration service in more detail with Client Signing, Server Signing, and Max Transmit, which affect the CIFS packet size, Figure 78:33 . The SonicWALL WXA series appliance joins the domain (becomes part of the domain) that is identified in the FQDN. The Join Domain Pop-up Window is displayed, Figure 78:34 .If the SonicWALL WXA series appliance has previously joined the domain, the Rejoin Domain button is displayed. Removes all information about the current domain that the SonicWALL WXA series appliance has joined. Tests the WFS Acceleration service. If the WFS Acceleration service is not working correctly, reconfigure the domain details, and then retest.
Figure 78:29 Configure Domain Pop-up Window
The FQDN for the Windows domain that the SonicWALL WXA series appliance will join. When checked (enabled), uses the NETBIOS name that is derived from the discovered domain.
Note Not necessary if the checkbox is selected.
Figure 78:30 Configure Hostname Pop-up Window
Input the desired hostname or leave the input field blank to use the default hostname.
Note If the device has already joined the domain, changing the host name requires the device to rejoin the domain.
Figure 78:31 Configure Kerberos Server Pop-up Window
Figure 78:32 Time Synchronization Pop-up Window
Use the Domain Controller for Time Synchronization: Checkbox When enabled (checked) the domain controller is used as the time syn chronization source. Overrides the domain controller synchronization by specify a NTP server in the required field. Validates that the NTP Server specified can be connected and that the server provide the current time.
Figure 78:33 Advanced Options Pop-up Window
Identifies the server message block (SMB) signing between the Son icWALL WXA series appliance and the Windows client. Identifies the SMB signing between the SonicWALL WXA series appliance and the server.
Figure 78:34 Join Domain Pop-up Window
Enter the username and password of the domain administrator account.
Shares Tab
The Shares tab configures the SonicWALL WXA series appliance to accelerate specific shares and servers.
Figure 78:35 WFS Acceleration > Shares
When clicked the Add Server pop-up is displayed, Figure 78:36 . This window allows you to configure a new remote server Displays an Edit and Delete buttons. Click the edit button to modify the configuration of the server. Click the delete button to remove the server from using WFS Acceleration. When the Edit button is clicked, the Edit Server Details window is displayed, Figure 78:36 . Displays an Edit and Delete button. Click the Edit button to modify the configuration of the share. Click the Delete button to remove the share from using the server. When the Edit button is clicked, The Edit Share Details pop-up window is displayed, Figure 78:37 .
Figure 78:36 Add Server and Edit Server Details Pop-up Windows
Remote Server Name: Text Field and Drop-down The name of the remote server. If you do not remember the name, select a name from the drop-down which displays a list of the detected servers (not always available).
Note The remote server can either be a Windows server or another SonicWALL WXA series appliance acting as a proxy server. Local Device Name: Text Field and Drop-down The name of the local device. If you do not remember the name, select a name from the drop-down which a list of the detected names (not always available).
Note The SonicWALL WXA series appliance will attempt to create a DNS record for each of the service principal name (SPN) aliases. The local device name must resolved to the public IP address. The DNS Server IP address is identified on the Domain Details Tab . When a file is requested, that is also available in the cache, the SonicWALL WXA series appliance serves the data from that cache as long as the cache file is valid. If the original file has changed, the parts of the cache that are still valid may be used. This process reduces the need for data to be sent over the network. This option can be overridden for individual shares. Default Cache Read Ahead: Text Field
(Add Server Pop-up only) To calculate this value, multiply the link latency (in milliseconds) by the measured site-to- site bandwidth in (kilobytes per second) and divide that by the number of simultaneous file access users. This option can be overridden for individual shares.
Example equation: BDP/<expected number of user sessions> where BDP = link rate in kilobytes * link latency.
Figure 78:37 Add Share and Edit Share Details Pop-up Windows
Share Name: Option with Text Field and Drop-down The name of the share to be added. If you do not remember the name, select a name from the drop-down which a list of available shares (not always available). The number of bytes in the text box that the cache reads ahead. This service is only func tional when the Cache Enabled checkbox is selected.Statistics Tab
The Statistics tab displays performance statistics for the WFS Acceleration service.
Figure 78:38 WFS Acceleration > Statistics
Refreshes the current page. The refresh interval can be entered in the text field. The maximum time interval that can be set is 600 seconds.
Click the Refresh symbol to manually update the page.
Click the Pause symbol to stop updates on the page.Tools Tab
The Tools tab provides diagnostic tools for the WFS Acceleration service.
The Diagnostic Tools drop-down provides the following selections:
• DNS Name Lookup — Performs a search on a specific Name or IP address, Figure 78:39 .
• Available Shares — Displays information about available shares on a specific host, Figure 78:40 .
• Test WFS Configuration — Performs a test on the WFS Acceleration configuration and validates connectivity, Figure 78:41 .
• List Kerberos Servers — Displays a list of Kerberos servers being used, Figure 78:42 .
Figure 78:39 DNS Name Lookup Panel The DNS Name Lookup Panel displays the following information:
Displays the primary DNS which was configured on SonicWALL NSA/TZ security appliance using the Network > DNS page or Network > DHCP Server > Edit > DNS/WINS tab.
Displays the secondary DNS which was configured on SonicWALL NSA/TZ security appliance using the Network > DNS page or Network > DHCP Server > Edit > DNS/WINS tab.
Allows you to search for available DNS names or IP addresses. Click Go to initiate the search. A response will be received from the DNS server. It is used to verify whether the WXA series appliance can reach the DNS server.
Note Lookup only works if the DNS server has reverse lookup zones configured.
Figure 78:40 Available Shares Panel The Available Shares Panel provides the following configuration options:
Note If the SonicWALL WXA series appliance has already joined the domain, you can use the SonicWALL WXA series appliance credentials and the username/password does not need to be entered.
Initiates the search. This will display a list of shares available on the server that the system administrator specified. It is used to verify the connection between the WXA series appliance and the server and that a list of shares can successfully be obtain from that server.
Figure 78:41 Test WFS Configuration Option The Test WFS Configuration Panel provides the following configuration options:
Figure 78:42 List Kerberos Servers Option The List Kerberos Server Panel provides the following configuration options: