Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tcp_sys
Visitor

fortigate firewall upgrade to 7.0.17 100F

After the firewall upgrade, a small number of clients occasionally experience timeouts when accessing the HTTPS applications deployed in our internal IDC. When  set policy NPU is disabled, everything returns to normal. Our internal applications are built on LVS. What are the common causes of this issue?

2 REPLIES 2
BillH_FTNT
Staff
Staff

Hi @tcp_sys 

Could you share some detailed information about your issue?

- What is the version before the upgrade?

- What is LVS ? 

- Does the traffic run over IPSEC VPN ?

- Could you share some output of "dia sys session list" ?

- Could you please share some output of NPU? (Please run the script below multiple times if you can enable NPU and make a test)

diag npu np6xlite register 0 | grep engine_status

diag vpn tunnel list

diag npu np6xlite dce 0

diag npu np6xlite anomaly-drop

fnsysctl cat /proc/net/np6xlite_0/pdq

fnsysctl cat /proc/net/np6xlite_0/hif-stats

fnsysctl cat /proc/net/np6xlite_0/hifdrop

fnsysctl cat /proc/net/np6xlite_0/osw

fnsysctl cat /proc/net/np6xlite_0/fos-perf

fnsysctl cat /proc/net/np6xlite_0/ipsec-perf

diag vpn ipsec status

diag vpn ike status

- If possible, please share your ticket number or configuration with me email bhoang@fortinet.com. I am Bill from Fortinet. I will do a production in my lab and cross-check the issue. Many Thanks

 

Regards

Bill

 

 

 

kaman
Staff
Staff

Hi tcp_sys,

NPU offload actually runs continuously in the background. NPUs (Network Processing Unit), as the name suggests, are specific processors. After FortiGate completes the 3-way handshake on the CPU, it transfers the relevant traffic to the NPU. Since the NPU is designed only to process network traffic, it processes this traffic much faster than the CPU.

The term 'NPU Offload' refers to traffic and and processes offloading to a special processing unit known as Network Processing Unit. This is a process known as Hardware Acceleration that helps reducing the CPU work load by allow the NPU to handle several processes including traffic inspection. It also allows for faster and more secure traffic handling by a dedicated chip that is built of different modules each for specific function.


Please refer to the documents below for more information:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Disable-Hardware-Acceleration/ta...


https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Explaining-the-NPU-Offload-field-in-...


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors