NSE4 · Question #381
Which of the following statements best describe the main requirements for a traffic session to be offload eligible to an NP6 processor? (Choose three.)
The correct answer is C. It does NOT require proxy-based inspection. D. Layer 4 protocol must be UDP, TCP, SCTP or ICMP. E. It does NOT require flow-based inspection.. For a FortiGate session to be offloaded by an NP6 processor, it must not require proxy-based or flow-based inspection, and its Layer 4 protocol must be UDP, TCP, SCTP, or ICMP.
Question
Which of the following statements best describe the main requirements for a traffic session to be offload eligible to an NP6 processor? (Choose three.)
Options
- ASession packets do NOT have an 802.1Q VLAN tag.
- BIt is NOT multicast traffic.
- CIt does NOT require proxy-based inspection.
- DLayer 4 protocol must be UDP, TCP, SCTP or ICMP.
- EIt does NOT require flow-based inspection.
How the community answered
(30 responses)- A7% (2)
- B10% (3)
- C83% (25)
Why each option
For a FortiGate session to be offloaded by an NP6 processor, it must not require proxy-based or flow-based inspection, and its Layer 4 protocol must be UDP, TCP, SCTP, or ICMP.
NP6 processors are fully capable of handling packets with 802.1Q VLAN tags, and the presence of such tags does not prevent a session from being offloaded.
NP6 processors can effectively offload multicast traffic, provided that other specific criteria for offloading are met, enhancing performance for multicast applications.
Sessions requiring proxy-based inspection, which involves deep packet analysis, content modification, and protocol negotiation at the application layer, cannot be offloaded to an NP6 processor as these tasks demand significant CPU resources.
NP6 processors are designed to accelerate and offload common Layer 4 protocols such as TCP, UDP, SCTP, and ICMP, which represent the bulk of standard network traffic flows, optimizing performance for these specific protocols.
Sessions that require flow-based inspection, which involves detailed security processing like antivirus, intrusion prevention, or web filtering that alters packet flow, are handled by the CPU and cannot be offloaded to an NP6 processor.
Concept tested: FortiGate NP6 offloading requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/606558/np-and-cp-processors-offloading
Topics
Community Discussion
No community discussion yet for this question.