NSE4 · Question #67
Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?
The correct answer is C. Both the phase 1 and phases 2 must use encryption algorithms supported by the NP6. This question asks for a critical condition enabling NP6 hardware acceleration for IPsec encryption and decryption.
Question
Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?
Options
- ANo protection profile can be applied over the IPsec traffic.
- BPhase-2 anti-replay must be disabled.
- CBoth the phase 1 and phases 2 must use encryption algorithms supported by the NP6.
- DIPsec traffic must not be inspected by any FortiGate session helper.
How the community answered
(24 responses)- A4% (1)
- B4% (1)
- C92% (22)
Why each option
This question asks for a critical condition enabling NP6 hardware acceleration for IPsec encryption and decryption.
Protection profiles (e.g., security inspection) typically prevent full session offloading but are not directly a condition for the NP6 to offload the *encryption/decryption* part if the algorithms are supported.
Phase-2 anti-replay protection is a standard security feature and generally does not prevent NP6 offloading of encryption/decryption, as NP6 chips often support it.
For IPsec traffic to be offloaded for encryption and decryption by an NP6 processor, both the Phase 1 (IKE) and Phase 2 (IPsec SA) configurations must use cryptographic algorithms that are natively supported by the NP6 chip's hardware acceleration engines.
While deep inspection by session helpers or security profiles prevents *full* session offloading, the NP6 can still offload the encryption/decryption phase even if the decrypted traffic is then sent to the CPU for inspection.
Concept tested: FortiGate NP6 IPsec hardware acceleration requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/hardware-acceleration/258597/np6-offloading-capabilities
Topics
Community Discussion
No community discussion yet for this question.