Hello All,
On a Fortigate 40F via the command "diagnose npu np6xlite dce", i can see the counter STAT_EHP1_INCR_FRAG increasing.
FGT40F (global) $ diagnose npu np6xlite dce
STAT_EHP1_INCR_FRAG:0000000000000147[a7]
FGT40F (global) $ diagnose npu np6xlite dce
STAT_EHP1_INCR_FRAG:0000000000000004[a7]
FGT40F (global) $ diagnose npu np6xlite dce
STAT_EHP1_INCR_FRAG:0000000000000003[a7]
FGT40F (global) $ diagnose npu np6xlite dce
STAT_EHP1_INCR_FRAG:0000000000000001[a7]
FGT40F (global) $
Someone know what this counter means ?
Hi @gmozgala
I think it's related to the statistics of dropped Fragment headers. You can repeat the test multiple times to observe how significant the changes are
Bill
Hi gmozgala,
Run the full command (including the 0) multiple times and observe the output carefully to determine if any packets are being dropped by the NP6 or NP6XLite process:
diagnose npu np6xlite dce 0
For example, the 'drop_ihp1_pktchk' counter refers to the number of dropped IP packets at the IHP1 level. This counter indicates the quantity of IP packets that were not successfully processed and were therefore dropped at this specific processing level within the NP6 processor.
Please refer to the document below for more information:
If you have found a solution, please like and accept it to make it easily accessible to others.
Regards,
Aman
User | Count |
---|---|
2624 | |
1393 | |
805 | |
671 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.