Fortinet black logo

Hardware Acceleration

policy-offload-level {disable | dos-offload | full-offload}

policy-offload-level {disable | dos-offload | full-offload}

Use the following command to configure how NP7 processors offload traffic.

config system npu

set policy-offload-level {disable | dos-offload | full-offload}

end

If your FortiGate has multiple VDOMs, this is a global command:

config global

config system npu

set policy-offload-level {disable | dos-offload | full-offload}

end

From individual VDOMs, you can use the following command to set the NP7 offload level for that VDOM.

config system settings

set policy-offload-level {disable | dos-offload | full-offload}

end

disable is the default setting for FortiGate with NP7 processors. Hyperscale firewall features are disabled. Offloading DoS policy sessions to NP7 processors is disabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

dos-offload offload DoS policy sessions to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload only available if your FortiGate is licensed for hyperscale firewall features. Select this option to enable hyperscale firewall features either globally or for the individual VDOM. For information about hyperscale firewall functionality, see the Hyperscale Firewall Guide. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.

policy-offload-level {disable | dos-offload | full-offload}

Use the following command to configure how NP7 processors offload traffic.

config system npu

set policy-offload-level {disable | dos-offload | full-offload}

end

If your FortiGate has multiple VDOMs, this is a global command:

config global

config system npu

set policy-offload-level {disable | dos-offload | full-offload}

end

From individual VDOMs, you can use the following command to set the NP7 offload level for that VDOM.

config system settings

set policy-offload-level {disable | dos-offload | full-offload}

end

disable is the default setting for FortiGate with NP7 processors. Hyperscale firewall features are disabled. Offloading DoS policy sessions to NP7 processors is disabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

dos-offload offload DoS policy sessions to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload only available if your FortiGate is licensed for hyperscale firewall features. Select this option to enable hyperscale firewall features either globally or for the individual VDOM. For information about hyperscale firewall functionality, see the Hyperscale Firewall Guide. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.