FG 60D and SPU/NPU offload
Hello Experts,
I am a user of FGT60D which is deployed in proxy-mode as firewall only. No UTM services.
I have not configured anything under Security Profiles
Recently, after upgrading my ISP bandwidth from 120Mbps to 500Mbps I have noticed my FG is now a bottleneck.
When I check Sessions widget in Dashboard I can see number of session and SPU 0.0%.
Executing diagnose sys session list command I can see that none of the sessions if offloaded to SPU/NPU with lots of reasons like no_ofld_reason: local
no_ofld_reason: non-npu-intf
When I connect directly to FG on DMZ port I get 100% of bandwidth.
When I connect directly to FG on Port1 which is a trunk (native vlan + a few tagged vlans; FG is DHCP server), I get 35% of bandwidth does not matter in which vlan.
My question is following:
FG60D has NP4Lite NPU which should allow to offload most of firewall processing from CPU to NPU. I have never deactivated it, what should I do to take advantage of NPU offloading?
