Skip to main content
MahmutKarali
Explorer
February 3, 2026
Solved

NPU is not enabled on the IPsec connection

  • February 3, 2026
  • 6 replies
  • 509 views

Hello Everyone,
I have a Fortios 7.6.4 Fortigate60F device. Even though I enabled the policy and IPsec NPU offloading settings for my IPsec connection, it shows npu_flag=00. Could this be related to the policy rules or the IPsec encryption algorithm?


If you could help me,

Best answer by funkylicious

certain authentication/encryption/dh combinations could lead to traffic not being offloaded to npu.

can you share what you are using ?

6 replies

funkylicious
SuperUser
SuperUser
February 3, 2026

certain authentication/encryption/dh combinations could lead to traffic not being offloaded to npu.

can you share what you are using ?

"jack of all trades, master of none"
MahmutKarali
Explorer
February 3, 2026

Ekran görüntüsü 2026-02-03 183501.pngEkran görüntüsü 2026-02-03 183507.png

 

VPN encryption and my DH group

funkylicious
SuperUser
SuperUser
February 3, 2026
MahmutKarali
Explorer
February 4, 2026

I'll change the DH group and encryption algorithms and try it myself.
I'll let you know.

MahmutKarali
Explorer
February 4, 2026

Unfortunately, it doesn't disappear. The NPU doesn't kick in. I need to make this setting for my IPSec performance.

funkylicious
SuperUser
SuperUser
February 4, 2026

i would look next into the firewall rule and security profiles attach to it - if any, maybe thats why it isnt offloaded

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!