Fortinet Document Library
Version:
7.2.0
7.0.5
7.0.1
Version:
7.0.0
6.4.9
6.4.8
Version:
6.4.6
6.4.5
6.2.9
Version:
6.2.7
6.0.0
5.6.0
Table of Contents
Hardware acceleration
What's new in FortiOS 7.0.1
What's new in FortiOS 7.0.0
Content processors (CP9, CP9XLite, CP9Lite)
CP9 capabilities
CP8 capabilities
Determining the content processor in your FortiGate unit
Viewing SSL acceleration status
Network processors (NP6, NP6XLite, and NP6Lite)
Accelerated sessions on FortiView All Sessions page
NP session offloading in HA active-active configuration
Configuring NP HMAC check offloading
Software switch interfaces and NP processors
Disabling NP offloading for firewall policies
Disabling NP offloading for individual IPsec VPN phase 1s
NP acceleration, virtual clustering, and VLAN MAC addresses
Determining the network processors installed in your FortiGate
NP hardware acceleration alters packet flow
NP6, NP6XLite, and NP6Lite traffic logging and monitoring
sFlow and NetFlow and hardware acceleration
Checking that traffic is offloaded by NP processors
Dedicated management CPU
Preventing packet ordering problems
Strict protocol header checking disables hardware acceleration
NTurbo and IPSA
NTurbo offloads flow-based processing
Disabling nTurbo for firewall policies
IPSA offloads flow-based advanced pattern matching
NP6, NP6XLite, and NP6Lite acceleration
NP6 session fast path requirements
NP6XLite processors
NP6Lite processors
NP6 processors and traffic shaping
IPv4 interface-based traffic shaping
NP Direct
Viewing your FortiGate NP6, NP6XLite, or NP6Lite processor configuration
Disabling NP6, NP6XLite, and NP6Lite hardware acceleration (fastpath)
Optimizing NP6 performance by distributing traffic to XAUI links
Enabling bandwidth control between the ISF and NP6 XAUI ports to reduce the number of dropped egress packets
Increasing NP6 offloading capacity using link aggregation groups (LAGs)
NP6 processors and redundant interfaces
Configuring inter-VDOM link acceleration with NP6 processors
Using VLANs to add more accelerated inter-VDOM link interfaces
Confirm that the traffic is accelerated
IPv6 IPsec VPN over NPU VDOM links
Disabling offloading IPsec Diffie-Hellman key exchange
Supporting IPsec anti-replay protection
Access control lists (ACLs)
NP6 HPE host protection engine
NP6 HPE packet flow and host queues
NP6 HPE configuration options
NP6 HPE and high priority traffic
Adjusting NP6 HPE BGP, SLBC, and BFD priorities
Monitoring NP6 HPE activity
Displaying NP6 HPE configuration and status information
Configuring individual NP6 processors
Per-session accounting for offloaded NP6, NP6XLite, and NP6Lite sessions
Multicast per-session accounting
Configuring NP6 session timeouts
Configure the number of IPsec engines NP6 processors use
Stripping clear text padding and IPsec session ESP padding
Disable NP6 and NP6XLite CAPWAP offloading
Optionally disable NP6 offloading of traffic passing between 10Gbps and 1Gbps interfaces
Offloading RDP traffic
NP6 session drift
Enhanced load balancing for LAG interfaces for NP6 platforms
Optimizing FortiGate 3960E and 3980E IPsec VPN performance
FortiGate 3960E and 3980E support for high throughput traffic streams
Recalculating packet checksums if the iph.reserved bit is set to 0
NP6 IPsec engine status monitoring
Interface to CPU mapping
Reducing the amount of dropped egress packets on LAG interfaces
Allowing offloaded IPsec packets that exceed the interface MTU
Offloading traffic denied by a firewall policy to reduce CPU usage
Configuring the QoS mode for NP6-accelerated traffic
Recovering from an internal link failure
Offloading UDP-encapsulated ESP traffic
NP6 get and diagnose commands
get hardware npu np6
diagnose npu np6
diagnose npu np6 npu-feature (verify enabled NP6 features)
diagnose npu np6xlite npu-feature (verify enabled NP6Lite features)
diagnose npu np6lite npu-feature (verify enabled NP6Lite features)
diagnose sys session/session6 list (view offloaded sessions)
diagnose sys session list no_ofld_reason field
diagnose npu np6 session-stats
(number of NP6 IPv4 and IPv6 sessions)
diagnose npu np6 ipsec-stats (NP6 IPsec statistics)
diagnose npu np6 sse-stats
(number of NP6 sessions and dropped sessions)
diagnose npu np6 dce
(number of dropped NP6 packets)
diagnose hardware deviceinfo nic
(number of packets dropped by an interface)
diagnose npu np6 synproxy-stats (NP6 SYN-proxied sessions and unacknowledged SYNs)
FortiGate NP6 architectures
FortiGate 300E and 301E fast path architecture
FortiGate 400E and 401E fast path architecture
FortiGate 500E and 501E fast path architecture
FortiGate 600E and 601E fast path architecture
FortiGate 800D fast path architecture
FortiGate 900D fast path architecture
FortiGate 1000D fast path architecture
FortiGate 1100E and 1101E fast path architecture
FortiGate 1200D fast path architecture
FortiGate 1500D fast path architecture
FortiGate 1500DT fast path architecture
FortiGate 2000E fast path architecture
FortiGate 2200E and 2201E fast path architecture
FortiGate 2500E fast path architecture
FortiGate 3000D fast path architecture
FortiGate 3100D fast path architecture
FortiGate 3200D fast path architecture
FortiGate 3300E and 3301E fast path architecture
FortiGate 3400E and 3401E fast path architecture
FortiGate 3600E and 3601E fast path architecture
FortiGate 3700D fast path architecture
FortiGate 3800D fast path architecture
FortiGate 3960E fast path architecture
FortiGate 3980E fast path architecture
FortiGate-5001E and 5001E1 fast path architecture
FortiController-5902D fast path architecture
FortiGate NP6XLite architectures
FortiGate 60F and 61F fast path architecture
FortiGate 80F, 81F, and 80F Bypass fast path architecture
FortiGate 100F and 101F fast path architecture
FortiGate NP6Lite architectures
FortiGate 100E and 101E fast path architecture
FortiGate 200E and 201E fast path architecture
Change log
Home
FortiGate / FortiOS 7.0.1
Hardware Acceleration
Hardware Acceleration
Hardware acceleration
What's new in FortiOS 7.0.1
What's new in FortiOS 7.0.0
Content processors (CP9, CP9XLite, CP9Lite)
CP9 capabilities
CP8 capabilities
Determining the content processor in your FortiGate unit
Viewing SSL acceleration status
Network processors (NP6, NP6XLite, and NP6Lite)
Accelerated sessions on FortiView All Sessions page
NP session offloading in HA active-active configuration
Configuring NP HMAC check offloading
Software switch interfaces and NP processors
Disabling NP offloading for firewall policies
Disabling NP offloading for individual IPsec VPN phase 1s
NP acceleration, virtual clustering, and VLAN MAC addresses
Determining the network processors installed in your FortiGate
NP hardware acceleration alters packet flow
NP6, NP6XLite, and NP6Lite traffic logging and monitoring
sFlow and NetFlow and hardware acceleration
Checking that traffic is offloaded by NP processors
Dedicated management CPU
Preventing packet ordering problems
Strict protocol header checking disables hardware acceleration
NTurbo and IPSA
NTurbo offloads flow-based processing
Disabling nTurbo for firewall policies
IPSA offloads flow-based advanced pattern matching
NP6, NP6XLite, and NP6Lite acceleration
NP6 session fast path requirements
NP6XLite processors
NP6Lite processors
NP6 processors and traffic shaping
IPv4 interface-based traffic shaping
NP Direct
Viewing your FortiGate NP6, NP6XLite, or NP6Lite processor configuration
Disabling NP6, NP6XLite, and NP6Lite hardware acceleration (fastpath)
Optimizing NP6 performance by distributing traffic to XAUI links
Enabling bandwidth control between the ISF and NP6 XAUI ports to reduce the number of dropped egress packets
Increasing NP6 offloading capacity using link aggregation groups (LAGs)
NP6 processors and redundant interfaces
Configuring inter-VDOM link acceleration with NP6 processors
Using VLANs to add more accelerated inter-VDOM link interfaces
Confirm that the traffic is accelerated
IPv6 IPsec VPN over NPU VDOM links
Disabling offloading IPsec Diffie-Hellman key exchange
Supporting IPsec anti-replay protection
Access control lists (ACLs)
NP6 HPE host protection engine
NP6 HPE packet flow and host queues
NP6 HPE configuration options
NP6 HPE and high priority traffic
Adjusting NP6 HPE BGP, SLBC, and BFD priorities
Monitoring NP6 HPE activity
Displaying NP6 HPE configuration and status information
Configuring individual NP6 processors
Per-session accounting for offloaded NP6, NP6XLite, and NP6Lite sessions
Multicast per-session accounting
Configuring NP6 session timeouts
Configure the number of IPsec engines NP6 processors use
Stripping clear text padding and IPsec session ESP padding
Disable NP6 and NP6XLite CAPWAP offloading
Optionally disable NP6 offloading of traffic passing between 10Gbps and 1Gbps interfaces
Offloading RDP traffic
NP6 session drift
Enhanced load balancing for LAG interfaces for NP6 platforms
Optimizing FortiGate 3960E and 3980E IPsec VPN performance
FortiGate 3960E and 3980E support for high throughput traffic streams
Recalculating packet checksums if the iph.reserved bit is set to 0
NP6 IPsec engine status monitoring
Interface to CPU mapping
Reducing the amount of dropped egress packets on LAG interfaces
Allowing offloaded IPsec packets that exceed the interface MTU
Offloading traffic denied by a firewall policy to reduce CPU usage
Configuring the QoS mode for NP6-accelerated traffic
Recovering from an internal link failure
Offloading UDP-encapsulated ESP traffic
NP6 get and diagnose commands
get hardware npu np6
diagnose npu np6
diagnose npu np6 npu-feature (verify enabled NP6 features)
diagnose npu np6xlite npu-feature (verify enabled NP6Lite features)
diagnose npu np6lite npu-feature (verify enabled NP6Lite features)
diagnose sys session/session6 list (view offloaded sessions)
diagnose sys session list no_ofld_reason field
diagnose npu np6 session-stats
(number of NP6 IPv4 and IPv6 sessions)
diagnose npu np6 ipsec-stats (NP6 IPsec statistics)
diagnose npu np6 sse-stats
(number of NP6 sessions and dropped sessions)
diagnose npu np6 dce
(number of dropped NP6 packets)
diagnose hardware deviceinfo nic
(number of packets dropped by an interface)
diagnose npu np6 synproxy-stats (NP6 SYN-proxied sessions and unacknowledged SYNs)
FortiGate NP6 architectures
FortiGate 300E and 301E fast path architecture
FortiGate 400E and 401E fast path architecture
FortiGate 500E and 501E fast path architecture
FortiGate 600E and 601E fast path architecture
FortiGate 800D fast path architecture
FortiGate 900D fast path architecture
FortiGate 1000D fast path architecture
FortiGate 1100E and 1101E fast path architecture
FortiGate 1200D fast path architecture
FortiGate 1500D fast path architecture
FortiGate 1500DT fast path architecture
FortiGate 2000E fast path architecture
FortiGate 2200E and 2201E fast path architecture
FortiGate 2500E fast path architecture
FortiGate 3000D fast path architecture
FortiGate 3100D fast path architecture
FortiGate 3200D fast path architecture
FortiGate 3300E and 3301E fast path architecture
FortiGate 3400E and 3401E fast path architecture
FortiGate 3600E and 3601E fast path architecture
FortiGate 3700D fast path architecture
FortiGate 3800D fast path architecture
FortiGate 3960E fast path architecture
FortiGate 3980E fast path architecture
FortiGate-5001E and 5001E1 fast path architecture
FortiController-5902D fast path architecture
FortiGate NP6XLite architectures
FortiGate 60F and 61F fast path architecture
FortiGate 80F, 81F, and 80F Bypass fast path architecture
FortiGate 100F and 101F fast path architecture
FortiGate NP6Lite architectures
FortiGate 100E and 101E fast path architecture
FortiGate 200E and 201E fast path architecture
Change log
7.0.1
7.2.0
7.0.5
7.0.1
7.0.0
6.4.9
6.4.8
6.4.6
6.4.5
6.2.9
6.2.7
6.0.0
5.6.0
Download PDF
Copy Link
FortiGate NP6XLite architectures
This chapter shows the NP6XLite architecture for FortiGate models that include NP6XLite processors.
FortiGate NP6XLite architectures
This chapter shows the NP6XLite architecture for FortiGate models that include NP6XLite processors.
Link
PDF
TOC