Fortinet black logo

Hardware Acceleration

Changing the policy offload level

Changing the policy offload level

You can use the following command to change the policy offload level for a FortiGate or for a VDOM in a FortiGate with NP7 processors

config system settings

set policy-offload-level {disable | dos-offload | full-offload}

end

disable disable hyperscale firewall features and disable offloading DoS policy sessions to NP7 processors for a FortiGate or for the current VDOM if multiple VDOMs are enabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors. This is the default policy offload level.

dos-offload offload DoS policy sessions to NP7 processors for the FortiGate or for the current VDOM if multiple VDOMs are enabled. DoS policy sessions bypass the CPU and are sent directly to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload enable hyperscale firewall features for the current hyperscale firewall VDOM. Sessions that are accepted by hyperscale firewall policies bypass the CPU and are sent directly to NP7 processors. This option is only available from a hyperscale firewall VDOM of a FortiGate licensed for hyperscale firewall features. DoS policy sessions also bypass the CPU and are sent directly to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.

For information about hyperscale firewall features, see the Hyperscale Firewall Guide.

Changing the policy offload level

You can use the following command to change the policy offload level for a FortiGate or for a VDOM in a FortiGate with NP7 processors

config system settings

set policy-offload-level {disable | dos-offload | full-offload}

end

disable disable hyperscale firewall features and disable offloading DoS policy sessions to NP7 processors for a FortiGate or for the current VDOM if multiple VDOMs are enabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors. This is the default policy offload level.

dos-offload offload DoS policy sessions to NP7 processors for the FortiGate or for the current VDOM if multiple VDOMs are enabled. DoS policy sessions bypass the CPU and are sent directly to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

full-offload enable hyperscale firewall features for the current hyperscale firewall VDOM. Sessions that are accepted by hyperscale firewall policies bypass the CPU and are sent directly to NP7 processors. This option is only available from a hyperscale firewall VDOM of a FortiGate licensed for hyperscale firewall features. DoS policy sessions also bypass the CPU and are sent directly to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.

For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.

For information about hyperscale firewall features, see the Hyperscale Firewall Guide.