| Description | This article describes the troubleshooting steps if the CGN Resource Allocation and port block allocation feature is not available or the CGN IP port range is not showing to adjust the range. |
| Scope | FortiGate (Hyperscale). |
| Solution |
If in Hyper Scale FortiGate, the CGN Resource Allocation and Port Block Allocation are not available, it is required to check if the hyper scale features are available or not.
CLI:
config firewall ippool edit CGN_POOL set type cgn-resource-allocation set cgn-port-start <port> set cgn-port-end <port> end
This feature might not be available if the hyperscale features are not enabled in FortiGate. The features can be enabled in the CLI:
config global end
If it is required to set up in the specific VDOMs in multi-vdom environment
config system settings set policy-offload-level full-offload
The 'full-offload' option activates hyperscale firewall capabilities for the VDOM, available only when the FortiGate has a valid hyperscale license. It enables offloading of DoS policy sessions and other offload-capable traffic to NP7 processors, while all remaining sessions continue to be handled by the CPU.
get system status | grep Hyperscale Hyperscale license: Enabled <------ If there is a license |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.