Enable Express Forwarding on a Security Policy
Focus
Focus
Network Security

Enable Express Forwarding on a Security Policy

Table of Contents

Enable Express Forwarding on a Security Policy

Enable Per Security Policy-based Express Forwarding to achieve ultra-low latency forwarding for time-sensitive traffic on select NGFW platforms.
Per Security Policy-based Express Forwarding is disabled by default. Enabling this feature on a security policy bypasses the Traffic Manager (TM) module functionality for sessions offloaded using that policy. This means features like Quality of Service (QoS) and Multicast will not be supported for traffic matching such policies.

Strata Cloud Manager

Enable Express Forwarding directly on your NGFW through the web interface when managed by Strata Cloud Manager.
  1. Select PoliciesSecurity.
  2. Select an existing security policy to modify or Add or Edit a new policy.
  3. In the policy rule settings, locate and select the Express Forwarding checkbox.
  4. Select OK to close the policy settings, then Commit the changes to your NGFW.

Panorama

Enable Express Forwarding on a security policy when your NGFWs are managed by Panorama.
  1. Log in to your Panorama web interface.
  2. Select PoliciesSecurity.
  3. Select the appropriate Device Group from the drop-down menu where your security policy resides.
  4. Select an existing security policy to modify or Add a new policy.
  5. In the policy rule settings, locate and select the Express Forwarding checkbox.
  6. Select OK to close the policy settings, then Commit the changes to Panorama.
  7. Push the committed configuration to your target NGFWs.

CLI

Configure Express Forwarding using the command-line interface for automation or direct device access.
  1. Access your firewall's command-line interface (CLI) or Panorama's CLI configuration mode.
  2. Enter configuration mode.
    #configure
  3. Enable express forwarding for a specific security policy.
    set vsys <vsys-name> rulebase security rules <security-pol-name> option express-forwarding yes
  4. (Optional) Disable express forwarding for a specific security policy.
    set vsys <vsys-name> rulebase security rules <security-pol-name> option express-forwarding no
  5. Commit the changes.