Fortinet black logo

Hyperscale Firewall Guide

Enabling hyperscale firewall features

Enabling hyperscale firewall features

Use the following global command to enable hyperscale firewall features for your FortiGate:

config system npu

set policy-offload-level full-offload

end

Once you have enabled global hyperscale firewall features, you must edit each hyperscale firewall VDOM and use the following command to enable hyperscale firewall features for that VDOM.

config system settings

set policy-offload-level full-offload

end

The following options are also available for this command:

default set this VDOM to use the global policy-offload-level setting.

dos-offload enable offloading sessions to the NP7 processors, but without enabling hyperscale firewall features.

full-offload enable hyperscale firewall features for the current hyperscale firewall VDOM.

Note

For more information about DoS policy hardware acceleration and how it varies depending on the policy offload level, see DoS policy hardware acceleration.

Enabling hyperscale firewall features

Use the following global command to enable hyperscale firewall features for your FortiGate:

config system npu

set policy-offload-level full-offload

end

Once you have enabled global hyperscale firewall features, you must edit each hyperscale firewall VDOM and use the following command to enable hyperscale firewall features for that VDOM.

config system settings

set policy-offload-level full-offload

end

The following options are also available for this command:

default set this VDOM to use the global policy-offload-level setting.

dos-offload enable offloading sessions to the NP7 processors, but without enabling hyperscale firewall features.

full-offload enable hyperscale firewall features for the current hyperscale firewall VDOM.

Note

For more information about DoS policy hardware acceleration and how it varies depending on the policy offload level, see DoS policy hardware acceleration.