Description | This article describes the functionality and configuration of DoS policy offload on FortiGate 100/101F and 200/201F models. |
Scope | FortiGate 100/101F and 200/201F models. |
Solution |
FortiGate 100F and 200F models use NP6Xlite ASIC processors and are equipped with a SYNPROXY module. This module enables partial offload of DoS features, enhancing performance and reducing CPU load.
This is because DoS/DDoS protection profiles on non-NP7-based FortiGates have always relied on the CPU.
To enable DoS policy offload on these models, use the following command:
config system settings set policy-offload-level dos-offload end
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.