Skip to main content
acappadonia
Staff
Staff
May 28, 2015

Technical Note: Hardware acceleration appears to be disabled on a FortiGate

  • May 28, 2015
  • 0 replies
  • 1810 views

Description

Hardware acceleration may be disabled on a FortiGate by the use of 'set check-protocol-header strict'.

If a configuration containing this setting (config sys global) is loaded on a device then hardware acceleration will not work and there is no way to know the cause.  However, if this setting is enabled through the CLI a warning is prompted:

FGT (global) # set check-protocol-header strict

Warning: This setting may break compatibility with some vendors and applications, cause loss of existing sessions,reduce overall system performance, drop ESP traffic from VPN tunnels terminated at this unit, and disable all hardware acceleration!

Do you want to continue? (y/n)
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!