config system npu-post
The FortiGate 1800F, 2600F, 3500F, 4200F, and 4400F models include the following command for configuring NP7 processors:
config system npu-post
set npu-group-effective-scope {0 | 1 | 2 | 3 | 255}
config port-npu-map
edit <interface-name>
set npu-group <group-name> <group-name> ...
end
end
end
For information about npu-group-effective-scope
, see npu-group-effective-scope {0 | 1 | 2 | 3 | 255}.
Use the config port-npu-map
command to configure NPU port mapping for the FortiGate 1800F, 2600F, 3500F, 4200F, and 4400F. You can use port mapping to assign data interfaces or LAGs to send traffic to selected NP7 processors or NP7 processor links.
Each NP7 processor has two 100-Gigabit KR links, numbered 0 and 1. Traffic passes to the NP7 over these links. By default the two links operate as a LAG that distributes sessions to the NP7 processor. You can configure NPU port mapping to assign data interfaces to use one or the other of the NP7 links instead of sending sessions over the LAG. If your FortiGate has multiple NP7 processors, you can configure port mapping to send sessions from specific data interfaces to specific NP7 processors or NP7 processor links.
The port mapping configuration can send sessions from more than one interface to the same NP7 processor.
<interface-name>
can be a physical interface or a LAG.
<group-name>
is the name of an NP7 processor, a group of NP7 processors, or an NP7 link that the interface is mapped to. You can add multiple <group-names>
to map traffic to multiple groups of NP7 processors and NP7 processor links. Group names can't np0overlap, for example you can't map an interface to both NP0 and NP0-link1.
<group-name>
can be:
All-NP
the interface connects to all links of all of the NP7 processors in the FortiGate. The integrated switch fabric load balances traffic from the interface among all of the links of all of the NP7 processors.
NPx
the name of the NP7 processor to link to. NP7 processor names are NP0, NP1, NP2 and so on. Each NP7 processor has two links. All traffic from the interface is load balanced between these two links.
NPx-to-NPy
the name of two NP7 processors to link to. For example, NP0-to-NP1
links to NP0 and NP1.
NPx-linky
the name of a single NP7 processor to link to. NPx
is the name of the NP7 processor. Each NP7 processor has two links, link0
and link1
. For example, NP3-link1
means link1 of NP3.
On the FortiGate 1800F, 2600F, 3500F, 4200F, and 4400F you can configure ISF load balancing to change the algorithm that the ISF uses to distribute data interface sessions to NP7 processors. ISF load balancing is configured for an interface, and distributes sessions from that interface to all NP7 processor LAGs. If you have configured NPU port mapping, ISF load balancing distributes sessions from the interface to the NP7 processors and links in the NPU port mapping configuration for that interface. See Configuring ISF load balancing. |
For more information about NPU port mapping for individual FortiGate models, see: