Changing the policy offload level
You can use the following command to change the policy offload level for a FortiGate or for a VDOM in a FortiGate with NP7 processors
config system settings
set policy-offload-level {disable | dos-offload | full-offload}
end
disable
disable hyperscale firewall features and disable offloading DoS policy sessions to NP7 processors for a FortiGate or for the current VDOM if multiple VDOMs are enabled. All sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors. This is the default policy offload level.
dos-offload
offload DoS policy sessions to NP7 processors for the FortiGate or for the current VDOM if multiple VDOMs are enabled. DoS policy sessions bypass the CPU and are sent directly to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.
full-offload
enable hyperscale firewall features for the current hyperscale firewall VDOM. Sessions that are accepted by hyperscale firewall policies bypass the CPU and are sent directly to NP7 processors. This option is only available from a hyperscale firewall VDOM of a FortiGate licensed for hyperscale firewall features. DoS policy sessions also bypass the CPU and are sent directly to NP7 processors. All other sessions are initiated by the CPU. Sessions that can be offloaded are sent to NP7 processors.
For more information about NP7 DoS policy hardware acceleration, see DoS policy hardware acceleration.
For information about hyperscale firewall features, see the Hyperscale Firewall Guide.