system : npu
 
npu
Use this command to configure the Network Processing Unit (NPU) for FortiGate units that support FB4. The NPU can take over encryption processing for its interfaces that would normally be performed by the main FortiGate unit CPU.
 
If you use the traffic-shaping-mode command, the bidirection option counts twice as much traffic. You need to allow twice the bandwidth as with unidirection.
Syntax
config system npu
set dec-offload-antireplay {enable | disable}
set dedicated-management-cpu {enable | disable}
set dedicated-tx-npu {enable | disable}
set enc-offload-antireplay {enable | disable}
set np6-cps-optimization-mode {enable | disable}
set npu-cascade-cluster {enable | disable}
set offload-ipsec-host {enable | disable}
next
end
Variable
Description
Default
dec-offload-antireplay {enable | disable}
Enable this option for the system to offload IPSEC packet encryption to FB4 when the ingress port of the tunnel is on FB4.
enable
dedicated-management-cpu {enable | disable}
Enable dedicating CPU #0 to management functions. This can affect performance. Available on some models.
disable
dedicated-tx-npu {enable | disable}
Enable a special mode in NP4, which handles slow path packets using a dedicated third NP4. This is available on model 3600C only.
disable
enc-offload-antireplay {enable | disable}
Enable this option for the system to offload IPSEC packet encryption to FB4 when the egress port of the tunnel is on FB4.
disable
np6-cps-optimization-mode {enable | disable}
Enable of disable NP6 CPS optimization mode.
disable
npu-cascade-cluster {enable | disable}
Enable cascade cluster mode on models 3950B and 3951B. Not available if sp-load-balance is enabled in system global.
disable
offload-ipsec-host {enable | disable}
Enable this option for the system to offload packet encryption to FB4 when the egress port of this packet is on FB4.
disable