Fortinet black logo

Hardware Acceleration

policy-offload-level {disable | dos-offload | full-offload}

policy-offload-level {disable | dos-offload | full-offload}

Set the global policy offload level for your FortiGate.

disable is the default setting for FortiGate with NP7 processors. Hyperscale firewall features are disabled. Offloading DoS policy sessions to NP7 processors is disabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

dos-offload offload DoS policy sessions to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload only available if your FortiGate is licensed for hyperscale firewall features. Select this option to enable hyperscale firewall features. For information about hyperscale firewall functionality, see the Hyperscale Firewall Guide. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

If you have enabled hyperscale firewall features, when you create a hyperscale firewall VDOM you must use the following command to enable hyperscale firewall features for that VDOM.

config system settings

set policy-offload-level full-offload

end

The following options are available for this command:

disable disable hyperscale firewall features and disable offloading DoS policy sessions to NP7 processors for this VDOM. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors. This is the default setting.

dos-offload offload DoS policy sessions to NP7 processors for this VDOM. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload enable hyperscale firewall features for the current hyperscale firewall VDOM. This option is only available if the FortiGate is licensed for hyperscale firewall features. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.

policy-offload-level {disable | dos-offload | full-offload}

Set the global policy offload level for your FortiGate.

disable is the default setting for FortiGate with NP7 processors. Hyperscale firewall features are disabled. Offloading DoS policy sessions to NP7 processors is disabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

dos-offload offload DoS policy sessions to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload only available if your FortiGate is licensed for hyperscale firewall features. Select this option to enable hyperscale firewall features. For information about hyperscale firewall functionality, see the Hyperscale Firewall Guide. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

If you have enabled hyperscale firewall features, when you create a hyperscale firewall VDOM you must use the following command to enable hyperscale firewall features for that VDOM.

config system settings

set policy-offload-level full-offload

end

The following options are available for this command:

disable disable hyperscale firewall features and disable offloading DoS policy sessions to NP7 processors for this VDOM. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors. This is the default setting.

dos-offload offload DoS policy sessions to NP7 processors for this VDOM. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload enable hyperscale firewall features for the current hyperscale firewall VDOM. This option is only available if the FortiGate is licensed for hyperscale firewall features. DoS policy sessions are also offloaded to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.