Fortinet black logo

Hardware Acceleration

Bandwidth control for NPU accelerated VDOM link interfaces

Bandwidth control for NPU accelerated VDOM link interfaces

NP7 processors include a module called the Virtual Egress Processor (VEP) that processes all traffic that passes through NPU accelerated VDOM link interfaces, including interfaces that have been added to NPU accelerated VDOM link interfaces (for example VLANs).

VEP allows you to tune improve overall performance by keeping accelerated VDOM link interfaces from consuming excessive NP7 bandwidth. By default, VEP imposes the following maximum bandwidth allocations on NPU accelerated VDOM link interfaces:

  • Maximum bandwidth supported across an NPU accelerated VDOM link with multiple sessions is 200Gbps.

  • Maximum bandwidth supported across an NPU accelerated VDOM link with one session is 100Gbps.

You can use the following command to change the VEP mode:

diagnose npu np7 vep-mode {100G-2 | 100G | 50G-4 | 50G-2 | 50G}

100G-2 the default VEP mode. Multiple session bandwidth limited to 200Gbps. Single session bandwidth limited to 100Gbps.

100G both multiple session and single-session bandwidth limited to 100Gbps.

50G-4 multiple session bandwidth limited to 200Gbps. Single session bandwidth limited to 50Gbps.

50G-2 multiple session bandwidth limited to 100Gbps. Single session bandwidth limited to 50Gbps.

50G multiple session bandwidth limited to 50Gbps. Single session bandwidth limited to 50Gbps.

After using this command to select a VEP mode, you must manually restart the FortiGate for the new VEP mode to take affect.

The VEP mode is applied per NP7 processor. If your FortiGate has multiple NP7 processors, they will all operate in the same VEP mode.

Bandwidth control for NPU accelerated VDOM link interfaces

NP7 processors include a module called the Virtual Egress Processor (VEP) that processes all traffic that passes through NPU accelerated VDOM link interfaces, including interfaces that have been added to NPU accelerated VDOM link interfaces (for example VLANs).

VEP allows you to tune improve overall performance by keeping accelerated VDOM link interfaces from consuming excessive NP7 bandwidth. By default, VEP imposes the following maximum bandwidth allocations on NPU accelerated VDOM link interfaces:

  • Maximum bandwidth supported across an NPU accelerated VDOM link with multiple sessions is 200Gbps.

  • Maximum bandwidth supported across an NPU accelerated VDOM link with one session is 100Gbps.

You can use the following command to change the VEP mode:

diagnose npu np7 vep-mode {100G-2 | 100G | 50G-4 | 50G-2 | 50G}

100G-2 the default VEP mode. Multiple session bandwidth limited to 200Gbps. Single session bandwidth limited to 100Gbps.

100G both multiple session and single-session bandwidth limited to 100Gbps.

50G-4 multiple session bandwidth limited to 200Gbps. Single session bandwidth limited to 50Gbps.

50G-2 multiple session bandwidth limited to 100Gbps. Single session bandwidth limited to 50Gbps.

50G multiple session bandwidth limited to 50Gbps. Single session bandwidth limited to 50Gbps.

After using this command to select a VEP mode, you must manually restart the FortiGate for the new VEP mode to take affect.

The VEP mode is applied per NP7 processor. If your FortiGate has multiple NP7 processors, they will all operate in the same VEP mode.