Fortinet black logo

Hardware Acceleration

Change log

Change log

Date

Change description

May 10, 2022

New sections:

Previous versions of this document incorrectly stated that NP6 processors support offloading DoS policy sessions. This has been corrected throughout the document as required.

Changes to the HPE section of Configuring individual NP6 processors.

March 2, 2022

Correction to Disabling NP offloading for firewall policies and Disabling nTurbo for firewall policies.

December 15, 2021

Moved information about improving CPS performance to sections describing the following FortiGate models that support this feature:

December 3, 2021

Corrections to FortiGate 80F, 81F, and 80F Bypass fast path architecture.

Correction to Disabling NP offloading for firewall policies.

New section Disabling nTurbo for firewall policies.

Removed the incorrect section "Disabling CP offloading for firewall policies".

September 17, 2021

Added more information about the NP6XLite processor to Network processors (NP6, NP6XLite, NP6Lite, and NP4) and NP6XLite processors.

More information added to NP6 session drift.

September 3, 2021

New section: NP acceleration, virtual clustering, and VLAN MAC addresses. Fixes to NP6 session drift. Removed the information about CP9 support for a true random number generator and entropy source from CP9 capabilities.

August 5, 2021

Updated NTurbo offloads flow-based processing to clarify that NTurbo also applies to IPsec VPN sessions.

Corrected errors in the section FortiGate 100F and 101F fast path architecture.

June 22, 2021

Corrected integrated switch fabric information in the following sections:

June 16, 2021

Added more information about bypass mode to:

April 12, 2021

Improved the information in Supporting IPsec anti-replay protection.

New section: FPM-7630E fast path architecture.

Corrected the output of the get hardware npu np6 port-list command in FortiGate 3600E and 3601E fast path architecture.

March 1, 2021

Corrected the get hardware npu np6 port-list command output in FortiGate 1100E and 1101E fast path architecture.

Updated the architecture sections for most E and F models to include more information about management/HA and data processing separation. For example, see the following:

December 18, 2020

New section: FortiGate 200F and 201F fast path architecture.

December 10, 2020

New section: FortiGate 80F, 81F, and 80F Bypass fast path architecture. More information about NetFlow support added to sFlow and NetFlow and hardware acceleration. Corrected the get hardware npu np6 port-list command output in FortiGate 1100E and 1101E fast path architecture.

New sections:

November 23, 2020

More information and corrections about SOC4 (NP6XLite and CP9XLite) and SOC3 (NP6Lite and CP9Lite).

October 19, 2020

Added bypass interface information to FortiGate 800D fast path architecture. Minor improvements to the bypass interface information in FortiGate 2500E fast path architecture. Other misc. changes and fixes.

September 14, 2020

Improved information about how for many more recent NP6 fast path architectures the HA interfaces are not connected to the NP6 processors. Information about bypass mode added to FortiGate 2500E fast path architecture. Corrected the output of the diagnose npu np6 port-list command in FortiGate 3960E fast path architecture.

Hardware architectures changed:

August 25, 2020

New section: FortiGate 100E and 101E fast path architecture.

Added a note about NP6 processors and traffic shaping counters to NP6 processors and traffic shaping.

Information about setting interface speeds added to FortiGate 3400E and 3401E fast path architecture and FortiGate 3600E and 3601E fast path architecture.

August 21, 2020

Added NP6XLite content.

July 20, 2020

Fixes and improvements to IPv4 interface-based traffic shaping.

July 8, 2020

Corrected the get hardware npu np6 port-list output in FortiGate 3400E and 3401E fast path architecture.

Added information about interface groups for the following models:

Added a note about ESP in UDP sessions (UDP port 4500) not been offloaded by NP6 processors to NP6 session fast path requirements.

Corrections to Dedicated management CPU.

Changes to Disabling NP6, NP6XLite, and NP6Lite hardware acceleration (fastpath).

May 21, 2020

New sections:

April 3, 2020

Improvements to the information about the HPE in Configuring individual NP6 processors.

New sections:

March 31, 2019

FortiOS 6.4 document release.

Change log

Date

Change description

May 10, 2022

New sections:

Previous versions of this document incorrectly stated that NP6 processors support offloading DoS policy sessions. This has been corrected throughout the document as required.

Changes to the HPE section of Configuring individual NP6 processors.

March 2, 2022

Correction to Disabling NP offloading for firewall policies and Disabling nTurbo for firewall policies.

December 15, 2021

Moved information about improving CPS performance to sections describing the following FortiGate models that support this feature:

December 3, 2021

Corrections to FortiGate 80F, 81F, and 80F Bypass fast path architecture.

Correction to Disabling NP offloading for firewall policies.

New section Disabling nTurbo for firewall policies.

Removed the incorrect section "Disabling CP offloading for firewall policies".

September 17, 2021

Added more information about the NP6XLite processor to Network processors (NP6, NP6XLite, NP6Lite, and NP4) and NP6XLite processors.

More information added to NP6 session drift.

September 3, 2021

New section: NP acceleration, virtual clustering, and VLAN MAC addresses. Fixes to NP6 session drift. Removed the information about CP9 support for a true random number generator and entropy source from CP9 capabilities.

August 5, 2021

Updated NTurbo offloads flow-based processing to clarify that NTurbo also applies to IPsec VPN sessions.

Corrected errors in the section FortiGate 100F and 101F fast path architecture.

June 22, 2021

Corrected integrated switch fabric information in the following sections:

June 16, 2021

Added more information about bypass mode to:

April 12, 2021

Improved the information in Supporting IPsec anti-replay protection.

New section: FPM-7630E fast path architecture.

Corrected the output of the get hardware npu np6 port-list command in FortiGate 3600E and 3601E fast path architecture.

March 1, 2021

Corrected the get hardware npu np6 port-list command output in FortiGate 1100E and 1101E fast path architecture.

Updated the architecture sections for most E and F models to include more information about management/HA and data processing separation. For example, see the following:

December 18, 2020

New section: FortiGate 200F and 201F fast path architecture.

December 10, 2020

New section: FortiGate 80F, 81F, and 80F Bypass fast path architecture. More information about NetFlow support added to sFlow and NetFlow and hardware acceleration. Corrected the get hardware npu np6 port-list command output in FortiGate 1100E and 1101E fast path architecture.

New sections:

November 23, 2020

More information and corrections about SOC4 (NP6XLite and CP9XLite) and SOC3 (NP6Lite and CP9Lite).

October 19, 2020

Added bypass interface information to FortiGate 800D fast path architecture. Minor improvements to the bypass interface information in FortiGate 2500E fast path architecture. Other misc. changes and fixes.

September 14, 2020

Improved information about how for many more recent NP6 fast path architectures the HA interfaces are not connected to the NP6 processors. Information about bypass mode added to FortiGate 2500E fast path architecture. Corrected the output of the diagnose npu np6 port-list command in FortiGate 3960E fast path architecture.

Hardware architectures changed:

August 25, 2020

New section: FortiGate 100E and 101E fast path architecture.

Added a note about NP6 processors and traffic shaping counters to NP6 processors and traffic shaping.

Information about setting interface speeds added to FortiGate 3400E and 3401E fast path architecture and FortiGate 3600E and 3601E fast path architecture.

August 21, 2020

Added NP6XLite content.

July 20, 2020

Fixes and improvements to IPv4 interface-based traffic shaping.

July 8, 2020

Corrected the get hardware npu np6 port-list output in FortiGate 3400E and 3401E fast path architecture.

Added information about interface groups for the following models:

Added a note about ESP in UDP sessions (UDP port 4500) not been offloaded by NP6 processors to NP6 session fast path requirements.

Corrections to Dedicated management CPU.

Changes to Disabling NP6, NP6XLite, and NP6Lite hardware acceleration (fastpath).

May 21, 2020

New sections:

April 3, 2020

Improvements to the information about the HPE in Configuring individual NP6 processors.

New sections:

March 31, 2019

FortiOS 6.4 document release.