This article describes troubleshooting IPsec-related issues on FortiGate devices using NP7Lite ASICs in G-series models. It focuses on interpreting output from the ipsec-perf debug file and identifying error counters that indicate problems in IPsec processing.
This is applicable to FortiGate devices with NP7Lite ASICs running on G-series models (e.g., FG-200G, FG-90G).
To gather performance and error metrics for the IPsec engine on NP7Lite, use the following command:
fnsysctl cat /proc/net/np7lite/np7lite_0/ipsec-perf
This outputs various counters related to inbound/outbound Security Association (SA) creation, deletion, update attempts, buffer management, and tunnel information.
Key areas of interest:
Observed Behavior:
Multiple iterations of these commands must be run, and if error counters increase along with reported IPsec performance issues, np7lite can contribute to the IPsec issues.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.