Fortinet white logo
Fortinet white logo

Hardware Acceleration

Change log

Change log

Date

Change description

March 31, 2026

New limitation added to NP7 and NP7Lite traffic shaping limitations: Changes to outbandwidth or egress shaping profiles on a physical or VLAN interface do not take effect for IPsec tunnels or sessions that are already established and offloaded by NP7 or NP7Lite (SOC5) processors. To apply the updated egress shaping settings, you must flush or reinstall the affected IPsec SAs and clear any offloaded sessions. Doing this rebuilds the IPsec tunnel and associated sessions using the new interface shaping configuration.

February 19, 2026

Corrected the following sections to show that interfaces 1 to 18 are connected to one ISF switch and interfaces 19 to 22 are connected to the other ISF switch:

February 17, 2026

Added information about NP7 and NP7Lite traffic shaping to NP7 and NP7Lite traffic shaping limitations.

Added information about a hardware issue that affects the FortiGate 3000F and 3001F, see FortiGate 3000F and 3001F fast path architecture.

January 29, 2026

FortiOS 7.2.13 document release.

December 16, 2025

DoS policy hardware acceleration is supported by NP7Lite (SOC5) processors for the following FortiGate models:

  • FortiGate 120G/121G

  • FortiGate 200G/201G

DoS policy hardware acceleration is not supported by the NP7Lite (SOC5) processors for the following FortiGate models and their rugged variations:

  • FortiGate 70G/71G

  • FortiGate 90G/91G

October 17, 2025

NP7 and NP7Lite processors do not support setting a priority in a traffic shaping profile. For more information, see NP7 and NP7Lite (SOC5) traffic shaping.

September 4, 2025

FortiOS 7.2.12 document release.

July 25, 2025

Added more information about NP7 and NP7Lite (SOC5) traffic shaping changes to FortiOS 7.2.11. See What's new for FortiOS 7.2.11, and NP7 and NP7Lite (SOC5) traffic shaping.

June 5, 2025

New section: FortiGate 700G and 701G fast path architecture.

May 13, 2025

Interface group updates to:

April 1, 2025

Added information about how FortiOS handles NTurbo sessions after an FGCP HA failover, see NTurbo offloads flow-based processing.

March 11, 2025

New sections:

March 7, 2025

New section, FortiGate 200G and 201G fast path architecture.

February 28, 2025

Added information about NP support for offloading NAT session setup for NAT44, NAT66, NAT64 and NAT46 traffic in the following sections:

New information about NP processor packet ordering and IPsec anti-replay protection, see:

February 12, 2025

FortiOS 7.2.11 document release.

December 16, 2024

Added more information about NP7 and NP6 performance monitoring:

October 30, 2024

Added more information about VNE and GRE tunnels and NP6 and NP7 acceleration, see:

September 19, 2024

FortiOS 7.2.10 document release.

August 15, 2024

FortiOS 7.2.9 document release.

June 17, 2024

NP6 offloading of ingress traffic shaping is not supported. This information has been added to NP6 session fast path requirements.

May 27, 2024

New option added to FortiOS 7.2.8 to configure how NP7 processors respond to SCTP checksum errors, see config fp-anomaly.

config system npu

config np-anomaly

set sctp-csum-err {allow | drop | trap-to-host}

end

The information in Configuring NP7 processors now just describes config system npu options for FortiGates with NP7 processors that are not licensed for hyperscale firewall. For information about the options of this command available on FortiGates with NP7 processors licensed for hyperscale firewall, see Configuring NP7 processors.

April 29, 2024

New section: FortiGate 900G and 901G fast path architecture.

April 24, 2024

NP7 offloading of ingress traffic shaping is not supported. This information has been added to NP7 session fast path requirements.

April 18, 2024

NP7 offloading of GRE over a loopback interface is not supported, see NP7 session fast path requirements, Tunneling protocols that can be offloaded by NP7 processors, and Protocols that can be offloaded by NP7 processors.

April 4, 2024

Updated Software switch interfaces and NP processors to explain that NP processors support offloading software switch traffic if intra-switch-policy is set to explicit and you have created firewall policies to allow traffic between interfaces in the software switch.

March 14, 2024

FortiOS 7.2.8 document release.

February 14, 2024

Corrections to hash-config {src-dst-ip | 5-tuple | src-ip}.

February 8, 2024

FortiOS 7.2.7 document release.

January 26, 2024

Updated NP7 session fast path requirements to include GRE.

December 22, 2023

New sections:

December 12, 2023

New section: FortiGate 40F fast path architecture.

October 20, 2023

Changes to NTurbo offloads flow-based processing.

October 18, 2023

New section: Performance reduction for NP6 processors with 1Gbps interfaces.

Changes to:

October 16, 2023

Changes to the following sections:

October 11, 2023

New sections:

Changes to most FortiGate fast path architecture descriptions.

September 28, 2023

FortiOS 7.2.6 document release.

September 7, 2023

Updates to NP7 performance optimized over KR links.

Changes to the following sections to correct information related to the SOC4:

August 10, 2023

Corrections to FortiGate NP7 architecture interface speeds, see FortiGate NP7 architectures.

Changes to FortiGate 3960E fast path architecture and FortiGate 3980E fast path architecture to explain that in multi-ISF systems, such as the FortiGate 3860E and FortiGate 3890E, NP6 offloading is not supported for LAGs containing interfaces connected to different ISF switches.

Corrected the section CP9 capabilities because FortiOS uses OpenSSL 3.0.x, which doesn't support the CP9 for SSL/TLS encryption and decryption.

July 17, 2023

Added information about NP6 and NP7 support for IPv6 SD-WAN segmentation over single relay sessions that include an IPsec VPN phase 1 configuration that enables VPN ID with IPIP encapsulation. See NP7 session fast path requirements and NP6 session fast path requirements.

June 30, 2023

Misc. changes throughout the document.

June 8, 2023

FortiOS 7.2.5 document release.

April 20, 2023

Corrections to NTurbo and IPSA.

April 4, 2023

Virtual network enabler (VNE) tunnel sessions are not offloaded by NP6 or NP6Lite (SOC3) processors. VNE tunnel sessions are offloaded by NP6XLite processors. Added a note about this to NP6 session fast path requirements.

February 17, 2023

Added all relevant options and corrected the information about the NP7 hash-config option, see hash-config {src-dst-ip | 5-tuple | src-ip}. Added a note about setting the hash-config for the FortiGate-3500F and 3501F to FortiGate 3500F and 3501F fast path architecture.

Deleted an incorrect statement about NP7 support for SSL VPN encryption from Network processors (NP7, NP7Lite, NP6, NP6XLite, and NP6Lite).

February 6, 2023

The dedicated management CPU feature is supported by the FortiGates with the NP6XLite (SOC4) processor. This information has been added to Improving GUI and CLI responsiveness (dedicated management CPU).

January 31, 2023

FortiOS 7.2.4 document release.

January 3, 2023

Corrected information about NTurbo support and interface policies, see NTurbo offloads flow-based processing.

Corrected the documented default values for many of the individual traffic types monitored by NP7 HPE, see NP7 HPE for individual traffic types.

December 30, 2022

New section: Tunneling protocols that can be offloaded by NP7 processors.

November 10, 2022

FortiOS 7.2.3 document release.

November 7, 2022

FortiOS 7.0.0 added support for creating LAGs between interfaces connected to different NP6 processors for FortiGates with multiple NP6 processors and no internal switch fabric. For more information, see Increasing NP6 offloading capacity using link aggregation groups (LAGs).

The following FortiGate models support this feature and the sections linked below have been updated with this information:

November 3, 2022

Removed the section "Viewing SSL acceleration status" because the get vpn status ssl hw-acceleration-status command has been removed. The command has been removed because FortiOS 7.2.2 uses OpenSSL 3.0.x, which doesn't support the CP9 functionality used by this command. Removed information about the FortiGate-1200D because this model is not supported by FortiOS 7.2.2.

October 4, 2022

FortiOS 7.2.2 document release. Corrections to FortiGate-5001E and 5001E1 fast path architecture.

Change log

Change log

Date

Change description

March 31, 2026

New limitation added to NP7 and NP7Lite traffic shaping limitations: Changes to outbandwidth or egress shaping profiles on a physical or VLAN interface do not take effect for IPsec tunnels or sessions that are already established and offloaded by NP7 or NP7Lite (SOC5) processors. To apply the updated egress shaping settings, you must flush or reinstall the affected IPsec SAs and clear any offloaded sessions. Doing this rebuilds the IPsec tunnel and associated sessions using the new interface shaping configuration.

February 19, 2026

Corrected the following sections to show that interfaces 1 to 18 are connected to one ISF switch and interfaces 19 to 22 are connected to the other ISF switch:

February 17, 2026

Added information about NP7 and NP7Lite traffic shaping to NP7 and NP7Lite traffic shaping limitations.

Added information about a hardware issue that affects the FortiGate 3000F and 3001F, see FortiGate 3000F and 3001F fast path architecture.

January 29, 2026

FortiOS 7.2.13 document release.

December 16, 2025

DoS policy hardware acceleration is supported by NP7Lite (SOC5) processors for the following FortiGate models:

  • FortiGate 120G/121G

  • FortiGate 200G/201G

DoS policy hardware acceleration is not supported by the NP7Lite (SOC5) processors for the following FortiGate models and their rugged variations:

  • FortiGate 70G/71G

  • FortiGate 90G/91G

October 17, 2025

NP7 and NP7Lite processors do not support setting a priority in a traffic shaping profile. For more information, see NP7 and NP7Lite (SOC5) traffic shaping.

September 4, 2025

FortiOS 7.2.12 document release.

July 25, 2025

Added more information about NP7 and NP7Lite (SOC5) traffic shaping changes to FortiOS 7.2.11. See What's new for FortiOS 7.2.11, and NP7 and NP7Lite (SOC5) traffic shaping.

June 5, 2025

New section: FortiGate 700G and 701G fast path architecture.

May 13, 2025

Interface group updates to:

April 1, 2025

Added information about how FortiOS handles NTurbo sessions after an FGCP HA failover, see NTurbo offloads flow-based processing.

March 11, 2025

New sections:

March 7, 2025

New section, FortiGate 200G and 201G fast path architecture.

February 28, 2025

Added information about NP support for offloading NAT session setup for NAT44, NAT66, NAT64 and NAT46 traffic in the following sections:

New information about NP processor packet ordering and IPsec anti-replay protection, see:

February 12, 2025

FortiOS 7.2.11 document release.

December 16, 2024

Added more information about NP7 and NP6 performance monitoring:

October 30, 2024

Added more information about VNE and GRE tunnels and NP6 and NP7 acceleration, see:

September 19, 2024

FortiOS 7.2.10 document release.

August 15, 2024

FortiOS 7.2.9 document release.

June 17, 2024

NP6 offloading of ingress traffic shaping is not supported. This information has been added to NP6 session fast path requirements.

May 27, 2024

New option added to FortiOS 7.2.8 to configure how NP7 processors respond to SCTP checksum errors, see config fp-anomaly.

config system npu

config np-anomaly

set sctp-csum-err {allow | drop | trap-to-host}

end

The information in Configuring NP7 processors now just describes config system npu options for FortiGates with NP7 processors that are not licensed for hyperscale firewall. For information about the options of this command available on FortiGates with NP7 processors licensed for hyperscale firewall, see Configuring NP7 processors.

April 29, 2024

New section: FortiGate 900G and 901G fast path architecture.

April 24, 2024

NP7 offloading of ingress traffic shaping is not supported. This information has been added to NP7 session fast path requirements.

April 18, 2024

NP7 offloading of GRE over a loopback interface is not supported, see NP7 session fast path requirements, Tunneling protocols that can be offloaded by NP7 processors, and Protocols that can be offloaded by NP7 processors.

April 4, 2024

Updated Software switch interfaces and NP processors to explain that NP processors support offloading software switch traffic if intra-switch-policy is set to explicit and you have created firewall policies to allow traffic between interfaces in the software switch.

March 14, 2024

FortiOS 7.2.8 document release.

February 14, 2024

Corrections to hash-config {src-dst-ip | 5-tuple | src-ip}.

February 8, 2024

FortiOS 7.2.7 document release.

January 26, 2024

Updated NP7 session fast path requirements to include GRE.

December 22, 2023

New sections:

December 12, 2023

New section: FortiGate 40F fast path architecture.

October 20, 2023

Changes to NTurbo offloads flow-based processing.

October 18, 2023

New section: Performance reduction for NP6 processors with 1Gbps interfaces.

Changes to:

October 16, 2023

Changes to the following sections:

October 11, 2023

New sections:

Changes to most FortiGate fast path architecture descriptions.

September 28, 2023

FortiOS 7.2.6 document release.

September 7, 2023

Updates to NP7 performance optimized over KR links.

Changes to the following sections to correct information related to the SOC4:

August 10, 2023

Corrections to FortiGate NP7 architecture interface speeds, see FortiGate NP7 architectures.

Changes to FortiGate 3960E fast path architecture and FortiGate 3980E fast path architecture to explain that in multi-ISF systems, such as the FortiGate 3860E and FortiGate 3890E, NP6 offloading is not supported for LAGs containing interfaces connected to different ISF switches.

Corrected the section CP9 capabilities because FortiOS uses OpenSSL 3.0.x, which doesn't support the CP9 for SSL/TLS encryption and decryption.

July 17, 2023

Added information about NP6 and NP7 support for IPv6 SD-WAN segmentation over single relay sessions that include an IPsec VPN phase 1 configuration that enables VPN ID with IPIP encapsulation. See NP7 session fast path requirements and NP6 session fast path requirements.

June 30, 2023

Misc. changes throughout the document.

June 8, 2023

FortiOS 7.2.5 document release.

April 20, 2023

Corrections to NTurbo and IPSA.

April 4, 2023

Virtual network enabler (VNE) tunnel sessions are not offloaded by NP6 or NP6Lite (SOC3) processors. VNE tunnel sessions are offloaded by NP6XLite processors. Added a note about this to NP6 session fast path requirements.

February 17, 2023

Added all relevant options and corrected the information about the NP7 hash-config option, see hash-config {src-dst-ip | 5-tuple | src-ip}. Added a note about setting the hash-config for the FortiGate-3500F and 3501F to FortiGate 3500F and 3501F fast path architecture.

Deleted an incorrect statement about NP7 support for SSL VPN encryption from Network processors (NP7, NP7Lite, NP6, NP6XLite, and NP6Lite).

February 6, 2023

The dedicated management CPU feature is supported by the FortiGates with the NP6XLite (SOC4) processor. This information has been added to Improving GUI and CLI responsiveness (dedicated management CPU).

January 31, 2023

FortiOS 7.2.4 document release.

January 3, 2023

Corrected information about NTurbo support and interface policies, see NTurbo offloads flow-based processing.

Corrected the documented default values for many of the individual traffic types monitored by NP7 HPE, see NP7 HPE for individual traffic types.

December 30, 2022

New section: Tunneling protocols that can be offloaded by NP7 processors.

November 10, 2022

FortiOS 7.2.3 document release.

November 7, 2022

FortiOS 7.0.0 added support for creating LAGs between interfaces connected to different NP6 processors for FortiGates with multiple NP6 processors and no internal switch fabric. For more information, see Increasing NP6 offloading capacity using link aggregation groups (LAGs).

The following FortiGate models support this feature and the sections linked below have been updated with this information:

November 3, 2022

Removed the section "Viewing SSL acceleration status" because the get vpn status ssl hw-acceleration-status command has been removed. The command has been removed because FortiOS 7.2.2 uses OpenSSL 3.0.x, which doesn't support the CP9 functionality used by this command. Removed information about the FortiGate-1200D because this model is not supported by FortiOS 7.2.2.

October 4, 2022

FortiOS 7.2.2 document release. Corrections to FortiGate-5001E and 5001E1 fast path architecture.