policy-offload-level {disable | dos-offload | full-offload}
Use the following command to configure how NP7 processors offload traffic.
config system npu
set policy-offload-level {disable | dos-offload | full-offload}
end
If your FortiGate has multiple VDOMs, this is a global command:
config global
config system npu
set policy-offload-level {disable | dos-offload | full-offload}
end
From individual VDOMs, you can use the following command to set the NP7 offload level for that VDOM.
config system settings
set policy-offload-level {disable | dos-offload | full-offload}
end
disable
is the default setting for FortiGate with NP7 processors. Hyperscale firewall features are disabled. Offloading DoS policy sessions to NP7 processors is disabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.
dos-offload
offload DoS policy sessions to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.
full-offload
only available if your FortiGate is licensed for hyperscale firewall features. Select this option to enable hyperscale firewall features either globally or for the individual VDOM. For information about hyperscale firewall functionality, see the Hyperscale Firewall Guide. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.
For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.