Skip to main content
suthomas1
New Member
June 19, 2020
Solved

npu link

  • June 19, 2020
  • 14 replies
  • 27054 views

Good day everyone,

 

I will appreciate all feedback on understanding what is the main difference between npu Vdom link & only Vdom link.

They appear to be two seperate things. i read about acceleration but didn't quite grasp it. 

 

So when should one use npu vdom & normal vdom link?

only creating the vdom link from interfaces, can it be used or does it have issues.

 

 

    Best answer by Toshi_Esumi

    Yes, of course. Also make sure it goes through only one/same npu from ingress to egress in case your model has multiple npus. It might make significant difference in performance.

    14 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    June 19, 2020

    Below doc for non-npu vlink says "VDOM link does not support traffic offload. If you want to use traffic offload, use NPU-VDOM-LINK."

    https://docs.fortinet.com...646/inter-vdom-routing

    So, if an ingress port1 in vdom1 is handled by npu1 and an egress port2 in vdom2 is handled by npu1 as well, the entire processes from the ingress to the egress could be offloaded to npu1 IF you use an npu1 vlink between two vdoms. If a non-npu vlink (or different npu vlink like npu2), it needs to come out from npu1 once and the CPU needs to handle it before hand it over to vdom2.

     

    suthomas1
    suthomas1Author
    New Member
    June 20, 2020

    Thank you Toshi.

    Then, is it better to use npu here to avoid CPU/software processing and help with hardware acceleration?

    Can the links between vdom be  both npu or non-npu ? how is it differentiated in configuration?

    Toshi_Esumi
    SuperUser
    SuperUser
    June 20, 2020

    Yes, of course. Also make sure it goes through only one/same npu from ingress to egress in case your model has multiple npus. It might make significant difference in performance.

    Toshi_Esumi
    SuperUser
    SuperUser
    February 15, 2022

    Don't touch "npu0_vlink0/1" config when you use VLAN subinterfaces to avoid confusion although you can use them. Just same as regular VLANs on regular interfaces/ports. Those are non-tagged parent interfaces.

     

    Toshi

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.