| Solution | FortiGate firewalls with NP7lite processors are unable to offload the VXLAN traffic over IPsec VPN. This can be confirmed by running the #diagnose sys session list command and checking the ofld_fail_reason field. session info: proto=6 proto_state=01 duration=2 expire=3597 timeout=3600 refresh_dir=both flags=00000000 socktype=0 sockport=0 av_idx=0 use=3 origin-shaper= reply-shaper= per_ip_shaper= class_id=0 ha_id=0 policy_dir=0 tunnel=/ vlan_cos=0/255 state=may_dirty npu statistic(bytes/packets/allow_err): org=349/5/1 reply=22713/18/1 tuples=2 tx speed(Bps/kbps): 0/0 rx speed(Bps/kbps): 0/0 orgin->sink: org pre->post, reply pre->post dev=41->42/42->41 gwy=1.1.2.2/0.0.0.0 hook=pre dir=org act=noop 1.1.1.1:60318->2.2.2.2:80(0.0.0.0:0) hook=post dir=reply act=noop 2.2.2.2:80->1.1.1.1:60318(0.0.0.0:0) pos/(before,after) 0/(0,0), 0/(0,0) src_mac=6e:55:50:3e:02:f9 misc=0 policy_id=10 pol_uuid_idx=1014 auth_info=0 chk_client_info=0 vd=5 serial=00000ec4 tos=ff/ff app_list=0 app=0 url_cat=0 rpdb_link_id=00000000 ngfwid=n/a npu_state=0x000400 ofld-O npu info: flag=0x81/0x81, offload=9/0, ips_offload=0/0, epid=20/0, ipid=6/6, vlan=0x05ab/0x05aa vlifid=6/0, vtag_in=0x05ab/0x0000 in_npu=1/0, out_npu=1/0, fwd_en=0/0, qid=7/0, ha_divert=0/0 no_ofld_reason: ofld_fail_reason(kernel, drv): none/none, none(0)/VXLAN-ib-not-offloaded(9) npu_state_err=00/00 The issue is currently under investigation and will be resolved in an upcoming firmware version. |