nerdexam
FortinetFortinet

NSE4 · Question #381

NSE4 Question #381: Real Exam Question with Answer & Explanation

The correct answer is C: It does NOT require proxy-based inspection.. For a FortiGate session to be offloaded by an NP6 processor, it must not require proxy-based or flow-based inspection, and its Layer 4 protocol must be UDP, TCP, SCTP, or ICMP.

Submitted by suresh_in· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Which of the following statements best describe the main requirements for a traffic session to be offload eligible to an NP6 processor? (Choose three.)

Options

  • ASession packets do NOT have an 802.1Q VLAN tag.
  • BIt is NOT multicast traffic.
  • CIt does NOT require proxy-based inspection.
  • DLayer 4 protocol must be UDP, TCP, SCTP or ICMP.
  • EIt does NOT require flow-based inspection.

Explanation

For a FortiGate session to be offloaded by an NP6 processor, it must not require proxy-based or flow-based inspection, and its Layer 4 protocol must be UDP, TCP, SCTP, or ICMP.

Common mistakes.

  • A. NP6 processors are fully capable of handling packets with 802.1Q VLAN tags, and the presence of such tags does not prevent a session from being offloaded.
  • B. NP6 processors can effectively offload multicast traffic, provided that other specific criteria for offloading are met, enhancing performance for multicast applications.

Concept tested. FortiGate NP6 offloading requirements

Reference. https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/606558/np-and-cp-processors-offloading

Topics

#NP6 offload#Hardware acceleration#Traffic processing#FortiGate ASICs

Community Discussion

No community discussion yet for this question.

Full NSE4 PracticeBrowse All NSE4 Questions