Facing Problem with Sangfor NGAF. Any Advice?
  

Newbie144873 Lv1Posted 26 Jul 2024 16:38

Hi everyone,
I'm currently experiencing some challenges with my Edge server setup and a Sangfor product. As someone relatively new to managing both hardware and software in this capacity, I could really use some advice from those more experienced.
Here are the specifics of my setup:
  • Server Setup: Edge server with high-end CPUs, ample RAM, and SSD storage capacity.
  • Sangfor Product: Sangfor Next-Generation Application Firewall (NGAF)


The Issues:
  • Performance Challenges: Sangfor NGAF is not performing as expected on my Edge server, particularly during high-traffic periods and extensive security scans. There are noticeable slowdowns and performance bottlenecks.
  • Installation and Configuration Difficulties: During the setup of Sangfor NGAF on my Edge server, I encountered several hurdles. While I managed to complete the installation, I suspect there may be lingering configuration issues affecting performance and usability.
  • Integration and Compatibility Concerns: I'm facing compatibility issues with certain network tools and third-party integrations within Sangfor NGAF. These issues are disrupting workflows and reducing efficiency in network security management.


Steps Taken So Far:
  • I've ensured that my hardware setup meets or exceeds the recommended specifications for Sangfor NGAF.
  • I've followed the installation and setup documentation for Sangfor NGAF meticulously.
  • I've reviewed and adjusted system configurations and resource allocations to optimize performance.


Despite my efforts, the challenges persist. Have any of you encountered similar issues with Sangfor NGAF on Edge servers? Are there specific configurations, optimizations, or troubleshooting techniques you've found effective? Any advice, insights, or recommended resources would be greatly appreciated.
Thank you in advance for your help!

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

Sheikh_Shani Lv2Posted 29 Jul 2024 23:08
  
Last edited by Sheikh_Shani 29 Jul 2024 23:17.


Hello Dear

It sounds like you’ve done a lot of the initial troubleshooting steps. Here are some more targeted suggestions and steps that might help address your issues:

Performance Challenges
1.Resource Allocation: Ensure that the NGAF has sufficient dedicated resources (CPU, RAM) and is not competing with other applications for these resources.

2.Traffic Shaping and QoS: Implement Quality of Service (QoS) policies to prioritize critical traffic and manage bandwidth allocation during high-traffic periods.

3.Load Balancing: If possible, use load balancing to distribute traffic more evenly across multiple devices or instances.

4.Firmware and Software Updates: Ensure that the NGAF firmware and software are up to date. Sometimes performance issues are resolved in newer updates.

5.Performance Tuning: Look into specific performance tuning settings within the NGAF. Sangfor documentation or support might provide recommendations for high-traffic environments.

Installation and Configuration Difficulties
1.Revisit Configuration Settings: Double-check all configuration settings. A small misconfiguration can lead to significant performance issues.

2.Default vs. Custom Settings: If you have customized settings, try reverting to the default settings and see if performance improves. If it does, reintroduce custom settings one by one to identify the problematic configuration.

3.Support and Community Resources: Utilize Sangfor support and community forums. Often, similar issues have been encountered by others, and solutions or workarounds are available.

4.Detailed Logs: Check detailed logs for any errors or warnings during the setup and operational phases. These logs can provide clues about what might be going wrong.

Integration and Compatibility Concerns
1.Compatibility Lists: Verify that the tools and third-party integrations you are using are listed as compatible with the specific version of the NGAF you are running.

2.API and Integration Settings: Ensure that all API and integration settings are correctly configured. Check for any updated integration guidelines from Sangfor or the third-party tool vendors.

3.Isolation Testing: Test the NGAF in isolation with each network tool to identify specific incompatibilities. This can help pinpoint which integrations are causing issues.

4.Feedback to Vendors: Reach out to both Sangfor and third-party vendors for compatibility support. Sometimes, they can provide patches or suggest configurations that resolve integration issues.

General Troubleshooting Steps
1.System Health Checks: Regularly perform system health checks to ensure all components are functioning optimally.

2.Network Monitoring: Use network monitoring tools to identify bottlenecks and performance degradation points.

3.Benchmarking: Benchmark the NGAF performance in a controlled environment to establish a baseline and compare it to the performance in the production environment.
Enrico Vanzetto Lv4Posted 29 Jul 2024 14:40
  
Hi, as i understood correctly, you have a Lenovo edgeserver with HCI installed as hypervisor. Then you deploy NGAF on it. Am i right?
If yes, please first check if your edgeserver (i don't know the exact model you are using) is mentioned on hci compatibility list.
Then, what resourceds you give to ngaf virtual machine? Could you please describe more the steps you made so far? About NGAF integration, which technology to try to configure with Ngaf?