Description | This article describes that with an hyperscale firewall, sessions are set up in the NP7 chip and also routed from there. There is a process to program kernel routes to the NP7 chip. For troubleshooting purposes, it can be necessary to display current routing information in the NP7 chip. |
Scope | FortiGate Hyperscale Firewall - 7.0, 7.2, 7.4. |
Solution |
For a specific IP routing information can be displayed with the below command:
FGT (GiFW-hw1) # diagnose lpmd route query 10.118.5.80
All routes programmed on NP7 can be printed with the below command :
FGT (GiFW-hw1) # diagnose lpmd route dump
In the above command output, route next-hop is specified with NHI parameter, for example :
=> VR: 0x0000, VDOM: 0500, IP: 10.118.5.80 / 32, NHI: 62
To find the gateway IP of NHI next-hop indexes below command can be used :
FGT (GiFW-hw1) # diag lpmd ktrie next_hop | grep 62 nhi: 62, family: 2, vdom: 500, ifindex: 20, oid: 137, vlan_id: 0 ref_cnt: 1, nh_flags: 0020, status: SYNCED | GW, next hop: 10.153.11.172 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.