nerdexam
Fortinet

NSE4 · Question #67

Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?

The correct answer is C. Both the phase 1 and phases 2 must use encryption algorithms supported by the NP6. This question asks for a critical condition enabling NP6 hardware acceleration for IPsec encryption and decryption.

Submitted by javi_es· Apr 18, 2026VPN and Routing

Question

Which is one of the conditions that must be met for offloading the encryption and decryption of IPsec traffic to an NP6 processor?

Options

  • ANo protection profile can be applied over the IPsec traffic.
  • BPhase-2 anti-replay must be disabled.
  • CBoth the phase 1 and phases 2 must use encryption algorithms supported by the NP6.
  • DIPsec traffic must not be inspected by any FortiGate session helper.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (22)

Why each option

This question asks for a critical condition enabling NP6 hardware acceleration for IPsec encryption and decryption.

ANo protection profile can be applied over the IPsec traffic.

Protection profiles (e.g., security inspection) typically prevent full session offloading but are not directly a condition for the NP6 to offload the *encryption/decryption* part if the algorithms are supported.

BPhase-2 anti-replay must be disabled.

Phase-2 anti-replay protection is a standard security feature and generally does not prevent NP6 offloading of encryption/decryption, as NP6 chips often support it.

CBoth the phase 1 and phases 2 must use encryption algorithms supported by the NP6.Correct

For IPsec traffic to be offloaded for encryption and decryption by an NP6 processor, both the Phase 1 (IKE) and Phase 2 (IPsec SA) configurations must use cryptographic algorithms that are natively supported by the NP6 chip's hardware acceleration engines.

DIPsec traffic must not be inspected by any FortiGate session helper.

While deep inspection by session helpers or security profiles prevents *full* session offloading, the NP6 can still offload the encryption/decryption phase even if the decrypted traffic is then sent to the CPU for inspection.

Concept tested: FortiGate NP6 IPsec hardware acceleration requirements

Source: https://docs.fortinet.com/document/fortigate/7.4.0/hardware-acceleration/258597/np6-offloading-capabilities

Topics

#IPsec Offloading#NP6 Processor#Hardware Acceleration#IPsec Configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice