FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.


Hardware acceleration may be disabled on a FortiGate by the use of 'set check-protocol-header strict'.

If a configuration containing this setting (config sys global) is loaded on a device then hardware acceleration will not work and there is no way to know the cause.  However, if this setting is enabled through the CLI a warning is prompted:

FGT (global) # set check-protocol-header strict

Warning: This setting may break compatibility with some vendors and applications, cause loss of existing sessions,reduce overall system performance, drop ESP traffic from VPN tunnels terminated at this unit, and disable all hardware acceleration!

Do you want to continue? (y/n)