NSE4 · Question #508
Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?
The correct answer is C. Phase 2 must have an encryption algorithm supported by the NP6. For an NP6 processor to offload IPsec traffic encryption and decryption, the configured Phase 2 encryption algorithm must be explicitly supported by the NP6 hardware.
Question
Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?
Options
- Ano protection profile can be applied over the IPsec traffic.
- BPhase-2 anti-replay must be disabled.
- CPhase 2 must have an encryption algorithm supported by the NP6.
- DIPsec traffic must not be inspected by any FortiGate session helper.
How the community answered
(23 responses)- C96% (22)
- D4% (1)
Why each option
For an NP6 processor to offload IPsec traffic encryption and decryption, the configured Phase 2 encryption algorithm must be explicitly supported by the NP6 hardware.
The application of protection profiles over IPsec traffic does not inherently prevent NP6 offloading if other conditions, particularly algorithm compatibility, are met.
Phase-2 anti-replay protection is a security feature and its state (enabled or disabled) is not a general condition for NP6 offloading of encryption/decryption.
NP6 processors are specialized hardware accelerators that can offload cryptographic operations, but only for specific encryption algorithms that they are designed to support, thus Phase 2 must use one of these algorithms.
While certain deep inspection features might interfere, a blanket statement that IPsec traffic must not be inspected by any FortiGate session helper is not the primary condition for NP6 crypto offloading.
Concept tested: FortiGate NP6 IPsec offloading requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/handbook/353457/hardware-acceleration
Topics
Community Discussion
No community discussion yet for this question.