Fortinet white logo
Fortinet white logo

Hyperscale Firewall Guide

Enable or disable NP7 MSE OFT

Enable or disable NP7 MSE OFT

You can use the following command to enable or disable using NP7 MSE OFT.

config system npu

set use-mse-oft {disable | enable}

end

By default, this option is set to enable and NP7 processors use MSE OFT. This is the default setting and usually results in optimal performance.

MSE OFT is involved with DoS anomaly scanning. In some cases and with some traffic patterns, after an extended operation period with DoS anomalies configured in both directions, NP7 processors can become stuck and FortiOS may write MSE depfail messages. This can result in the PLE getting stuck and PBA leaks can be seen resulting in performance reductions or blocked traffic.

In many cases, you can resolve these issues by setting use-mse-oft to disable. Disabling MSE OFT, sets the MSE size to 0, effectively disabling MSE OFT. If your FortiGate is experiencing the issues described above, disabling MSE OFT may improve overall performance.

Changing use-mse-oft causes the FortiGate to restart.

Note

A configuration change that causes a FortiGate to restart can disrupt the operation of an FGCP cluster. If possible, you should make this configuration change to the individual FortiGates before setting up the cluster. If the cluster is already operating, you should temporarily remove the secondary FortiGate(s) from the cluster, change the configuration of the individual FortiGates and then re-form the cluster. You can remove FortiGate(s) from a cluster using the Remove Device from HA cluster button on the System > HA GUI page. For more information, see Disconnecting a FortiGate.

Enable or disable NP7 MSE OFT

Enable or disable NP7 MSE OFT

You can use the following command to enable or disable using NP7 MSE OFT.

config system npu

set use-mse-oft {disable | enable}

end

By default, this option is set to enable and NP7 processors use MSE OFT. This is the default setting and usually results in optimal performance.

MSE OFT is involved with DoS anomaly scanning. In some cases and with some traffic patterns, after an extended operation period with DoS anomalies configured in both directions, NP7 processors can become stuck and FortiOS may write MSE depfail messages. This can result in the PLE getting stuck and PBA leaks can be seen resulting in performance reductions or blocked traffic.

In many cases, you can resolve these issues by setting use-mse-oft to disable. Disabling MSE OFT, sets the MSE size to 0, effectively disabling MSE OFT. If your FortiGate is experiencing the issues described above, disabling MSE OFT may improve overall performance.

Changing use-mse-oft causes the FortiGate to restart.

Note

A configuration change that causes a FortiGate to restart can disrupt the operation of an FGCP cluster. If possible, you should make this configuration change to the individual FortiGates before setting up the cluster. If the cluster is already operating, you should temporarily remove the secondary FortiGate(s) from the cluster, change the configuration of the individual FortiGates and then re-form the cluster. You can remove FortiGate(s) from a cluster using the Remove Device from HA cluster button on the System > HA GUI page. For more information, see Disconnecting a FortiGate.