nerdexam
Fortinet

NSE4 · Question #508

Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?

The correct answer is C. Phase 2 must have an encryption algorithm supported by the NP6. For an NP6 processor to offload IPsec traffic encryption and decryption, the configured Phase 2 encryption algorithm must be explicitly supported by the NP6 hardware.

Submitted by anna_se· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?

Options

  • Ano protection profile can be applied over the IPsec traffic.
  • BPhase-2 anti-replay must be disabled.
  • CPhase 2 must have an encryption algorithm supported by the NP6.
  • DIPsec traffic must not be inspected by any FortiGate session helper.

How the community answered

(23 responses)
  • C
    96% (22)
  • D
    4% (1)

Why each option

For an NP6 processor to offload IPsec traffic encryption and decryption, the configured Phase 2 encryption algorithm must be explicitly supported by the NP6 hardware.

Ano protection profile can be applied over the IPsec traffic.

The application of protection profiles over IPsec traffic does not inherently prevent NP6 offloading if other conditions, particularly algorithm compatibility, are met.

BPhase-2 anti-replay must be disabled.

Phase-2 anti-replay protection is a security feature and its state (enabled or disabled) is not a general condition for NP6 offloading of encryption/decryption.

CPhase 2 must have an encryption algorithm supported by the NP6.Correct

NP6 processors are specialized hardware accelerators that can offload cryptographic operations, but only for specific encryption algorithms that they are designed to support, thus Phase 2 must use one of these algorithms.

DIPsec traffic must not be inspected by any FortiGate session helper.

While certain deep inspection features might interfere, a blanket statement that IPsec traffic must not be inspected by any FortiGate session helper is not the primary condition for NP6 crypto offloading.

Concept tested: FortiGate NP6 IPsec offloading requirements

Source: https://docs.fortinet.com/document/fortigate/7.4.0/handbook/353457/hardware-acceleration

Topics

#IPsec#Hardware Acceleration#NP6 Processor#Performance Optimization

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice