Chapter 10 IPsec VPN : Hardware offloading and acceleration : Overview : Packet offloading requirements
  
Packet offloading requirements
In addition to the session requirements, the packets themselves must meet fast-path requirements:
Incoming packets must not be fragmented.
Outgoing packets must be 385 bytes or larger after any fragmentation. This means the configured MTU (Maximum Transmission Unit) for the network processors’ interfaces must have an MTU of 385 bytes or larger.
If packet offloading requirements are not met, an individual packet will use the FortiGate unit main processing resources, regardless of whether other packets in the session are offloaded to the specialized network processors.