Fortinet Document Library

Version:

Version:

Version:

Version:

Version:


Table of Contents

Hardware Acceleration

Change log

Date

Change description

May 10, 2022

New sections:

Previous versions of this document incorrectly stated that NP6 processors support offloading DoS policy sessions. This has been corrected throughout the document as required.

Changes to the HPE section of NP6 HPE host protection engine.

March 1, 2022

Removed an incorrect statement from the section Increasing NP6 offloading capacity using link aggregation groups (LAGs).

Correction to Disabling NP offloading for firewall policies and Disabling nTurbo for firewall policies.

December 15, 2021

Moved information about improving CPS performance to sections describing the following FortiGate models that support this feature:

Removed information about older NP and CP processors and removed information about SP processors since older FortiGate models that include this hardware are not supported by FortiOS 7.0.

December 3, 2021

Correction to Disabling NP offloading for firewall policies.

New section Disabling nTurbo for firewall policies.

Removed the incorrect section "Disabling CP offloading for firewall policies".

September 17, 2021

Added more information about the NP6XLite processor to Network processors (NP6, NP6XLite, and NP6Lite) and NP6XLite processors.

September 3, 2021

New and improved content:

August 31, 2021

New section: NP acceleration, virtual clustering, and VLAN MAC addresses. Fixes to NP6 session drift. Removed the information about CP9 support for a true random number generator and entropy source from CP9 capabilities.

August 4, 2021

Added a note about NP6 processors not offloading sessions between two EMAC VLANs on NPU inter-VDOM link interfaces to Using VLANs to add more accelerated inter-VDOM link interfaces.

Updated NTurbo offloads flow-based processing to clarify that NTurbo also applies to IPsec VPN sessions.

Corrected errors in the section FortiGate 100F and 101F fast path architecture.

June 22, 2021

Updated NP6 session fast path requirements to list support for offloading UDP traffic with a destination port of 4500 (ESP-in-UDP traffic). New section: Offloading UDP-encapsulated ESP traffic.

Corrected integrated switch fabric information in the following sections:

April 12, 2021

Improved the information in Supporting IPsec anti-replay protection.

Corrected the output of the get hardware npu np6 port-list command in FortiGate 3600E and 3601E fast path architecture.

April 7, 2021

FortiOS 7.0 document release.

Change log

Date

Change description

May 10, 2022

New sections:

Previous versions of this document incorrectly stated that NP6 processors support offloading DoS policy sessions. This has been corrected throughout the document as required.

Changes to the HPE section of NP6 HPE host protection engine.

March 1, 2022

Removed an incorrect statement from the section Increasing NP6 offloading capacity using link aggregation groups (LAGs).

Correction to Disabling NP offloading for firewall policies and Disabling nTurbo for firewall policies.

December 15, 2021

Moved information about improving CPS performance to sections describing the following FortiGate models that support this feature:

Removed information about older NP and CP processors and removed information about SP processors since older FortiGate models that include this hardware are not supported by FortiOS 7.0.

December 3, 2021

Correction to Disabling NP offloading for firewall policies.

New section Disabling nTurbo for firewall policies.

Removed the incorrect section "Disabling CP offloading for firewall policies".

September 17, 2021

Added more information about the NP6XLite processor to Network processors (NP6, NP6XLite, and NP6Lite) and NP6XLite processors.

September 3, 2021

New and improved content:

August 31, 2021

New section: NP acceleration, virtual clustering, and VLAN MAC addresses. Fixes to NP6 session drift. Removed the information about CP9 support for a true random number generator and entropy source from CP9 capabilities.

August 4, 2021

Added a note about NP6 processors not offloading sessions between two EMAC VLANs on NPU inter-VDOM link interfaces to Using VLANs to add more accelerated inter-VDOM link interfaces.

Updated NTurbo offloads flow-based processing to clarify that NTurbo also applies to IPsec VPN sessions.

Corrected errors in the section FortiGate 100F and 101F fast path architecture.

June 22, 2021

Updated NP6 session fast path requirements to list support for offloading UDP traffic with a destination port of 4500 (ESP-in-UDP traffic). New section: Offloading UDP-encapsulated ESP traffic.

Corrected integrated switch fabric information in the following sections:

April 12, 2021

Improved the information in Supporting IPsec anti-replay protection.

Corrected the output of the get hardware npu np6 port-list command in FortiGate 3600E and 3601E fast path architecture.

April 7, 2021

FortiOS 7.0 document release.