FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Article Id 196508


Hardware acceleration has many benefits including lowing CPU utilization, increasing throughout and reducing latency.


For detailed coverage of factors affecting hardware acceleration, see the Hardware Acceleration Handbook for your FortiOS version level.


The following document highlights a few of the more common factors and serves as a quick checklist.  The specifics may depends on your model and its mix of network processor (NP), content processor (CP) and other hardware acceleration capabilities.

Using factory default settings, offload of traffic forwarding to the NPU occurs automatically.

Enabling certain features will disable offload for affected traffic:

  •     use of session-helper
  •     proxy-based inspection
  •     flow-based inspection (unless accelerated security processing is available e.g., nTurbo)
  •     use of traffic shaper
  •     WAN Optimization / Web Proxy

In addition, the following traffic is only handled by the CPU:

  •     Dynamic routing
  •     High Availability packets
  •     Management traffic


Related Articles

Technical Note : Hardware acceleration and redundant/aggregate interfaces

Is a session offloaded? (hardware acceleration)

Technical Note : Traffic acceleration on inter-VDOM links - FortiOS 5.0 - NP4 based devices (npu0-vl...