Created on
04-07-2022
05:37 AM
Edited on
07-13-2023
12:20 AM
By
Jean-Philippe_P
Description | This article describes when Hardware Acceleration for IPSec configured on the Loopback interface is supported. |
Scope | FortiGate. |
Solution |
For FortiGates with NP6 or NP6lite and NP7 (FortiOS up to 7.0.5. or 7.2.0), when IPSec VPN is configured with the source interface as a Loopback interface, then may lead to performance issues as the loopback interface does not support hardware acceleration. It is recommended to configure IPSec on npu-vlink in case of multi-VDOM or use a Physical interface.
For devices with NP7, running on FortiOS 7.0.6 and 7.2.1 and above, hardware acceleration is supported on Loopback interfaces.
In order to verify such configuration in your unit, you may issue the command "diagnose vpn tunnel list" and identify your tunnel.
For easier reading, a sample omitted output will be generated:
name=to10.183.4.123 ver=2 serial=1 172.16.1.1:0->10.183.4.123:0 tun_id=10.183.4.123 tun_id6=::10.183.4.123 dst_mtu=0 dpd-link=on weight=1
There are two key factors that should be noted:
|