Optimizing HA hardware session synchronization performance
The FortiGate-4200F, 4201F, 4400F, and 4401F models include HA1, HA2, AUX1, and AUX2 interfaces that can be used to optimize HA hardware session synchronization performance. For optimal HA hardware session sync performance, make sure the interface you assign to hw-session-sync-dev
is included in the following configuration:
config system npu
config port-path-option
set ports-using-npu {ha1 ha2 aux1 aux2}
end
ports-using-npu
select one or more interfaces to use for HA hardware session synchronization or hardware logging.
Changing the |
When you add an interface to this list, HA hardware session synchronization or hardware logging packets can be sent directly from NP7 processors over the ISF to that interface, bypassing the CPU. If you don't add interfaces to this list, the CPU is not bypassed, resulting in lower HA hardware session synchronization or hardware logging performance.
You can also use this command to improve hardware logging performance. See Optimizing hardware logging performance using AUX interfaces. |
Interfaces added to the ports-using-npu
list should not be used for other traffic. For example, if you use ha1 and ha2 as HA heartbeat interfaces, use aux1 or aux2 for HA hardware session synchronization.
For example, create the following configuration to use ha1 and ha2 as the HA heartbeat interfaces and aux1 as the HA hardware session synchronization interface:
config system ha
set hbdev ha1 100 ha2 100
set session-pickup enable
set hw-session-sync-dev aux1
end
config system npu
config port-path-option
set ports-using-npu aux1
end
You can use ha1 or ha2 for HA hardware session synchronization if you use different interfaces for the HA heartbeat. Only one interface can be used as the hardware session synchronization interface and this interface cannot be a LAG.
You can also configure a data interface to be the hardware session synchronization interface, for example:
config system ha
set hw-session-sync-dev port5
end
No special configuration is required if you use a data interface. However, the data interface should not be used for any other traffic. Hardware session sync performance is optimal if you use one of the ha1, ha2, aux1 or aux2 interfaces.