VPN and ASIC offload
This topic provides a brief introduction to VPN traffic offloading.
IPsec traffic processed by NPU
- Check the device ASIC information. For example, a FortiGate 900D has an NP6 and a CP8.
# get hardware status Model name: [[QualityAssurance62/FortiGate]]-900D ASIC version: CP8 ASIC SRAM: 64M CPU: Intel(R) Xeon(R) CPU E3-1225 v3 @ 3.20GHz Number of CPUs: 4 RAM: 16065 MB Compact Flash: 1925 MB /dev/sda Hard disk: 244198 MB /dev/sdb USB Flash: not available Network Card chipset: [[QualityAssurance62/FortiASIC]] NP6 Adapter (rev.)
- Check port to NPU mapping.
# diagnose npu np6 port-list Chip XAUI Ports Max Cross-chip Speed offloading ---- np6_0 0 1. port17 1G Yes 1. port18 1G Yes 1. port19 1G Yes 1. port20 1G Yes 1. port21 1G Yes 1. port22 1G Yes 1. port23 1G Yes 1. port24 1G Yes 1. port27 1G Yes 1. port28 1G Yes 1. port25 1G Yes 1. port26 1G Yes 1. port31 1G Yes 1. port32 1G Yes 1. port29 1G Yes 1. port30 1G Yes 1. portB 10G Yes 1. ---- np6_1 0 1. port1 1G Yes 1. port2 1G Yes 1. port3 1G Yes 1. port4 1G Yes 1. port5 1G Yes 1. port6 1G Yes 1. port7 1G Yes 1. port8 1G Yes 1. port11 1G Yes 1. port12 1G Yes 1. port9 1G Yes 1. port10 1G Yes 1. port15 1G Yes 1. port16 1G Yes 1. port13 1G Yes 1. port14 1G Yes 1. portA 10G Yes 1. ----