FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nevan
Staff
Staff
Article Id 402450
Description This article describes the troubleshooting steps if the CGN Resource Allocation and port block allocation feature is not available or the CGN IP port range is not showing to adjust the range.
Scope FortiGate (Hyperscale).
Solution

If in Hyper Scale FortiGate, the CGN Resource Allocation and Port Block Allocation are not available, it is required to check if the hyper scale features are available or not.

 

CLI: 

 

config firewall ippool

     edit CGN_POOL

          set type cgn-resource-allocation

          set cgn-port-start <port>

          set cgn-port-end <port>

end

 

This feature might not be available if the hyperscale features are not enabled in FortiGate. The features can be enabled in the CLI:

 

config global
    config system npu
         set policy-offload-level full-offload

end

 

If it is required to set up in the specific VDOMs in multi-vdom environment

 

config system settings

     set policy-offload-level full-offload
end

 

The 'full-offload' option activates hyperscale firewall capabilities for the VDOM, available only when the FortiGate has a valid hyperscale license. It enables offloading of DoS policy sessions and other offload-capable traffic to NP7 processors, while all remaining sessions continue to be handled by the CPU.

It is also necessary to check if the unit has the hyperscale license activated or not without which the features might not be available at all.

To check the license from the CLI: 

 

get system status | grep Hyperscale
<blank>                                       <----- If there is no license

Hyperscale license: Enabled      <------ If there is a license 

 
If there are no licenses, it will show nothing, whereas if there is a license activated for the unit, it will show 'Enabled' status.

Related arrticle:
Technical Tip: Hyperscale Hardware Logs do not appear in FortiView on the FortiGate

Contributors