Enable Per Security Policy-based Express Forwarding to achieve ultra-low latency
forwarding for time-sensitive traffic on select NGFW platforms.
Per Security Policy-based Express Forwarding is disabled by default. Enabling this
feature on a security policy bypasses the Traffic Manager (TM) module functionality
for sessions offloaded using that policy. This means features like Quality of
Service (QoS) and Multicast will not be supported for traffic matching such
policies.
Strata Cloud Manager
Enable Express Forwarding directly on your NGFW through the web interface when
managed by Strata Cloud Manager.
Select .
Select an existing security policy to modify or
Add or
Edit a new policy.
In the policy rule settings, locate and select the
Express
Forwarding checkbox.
Select OK to close the policy settings, then
Commit the changes to your NGFW.
Panorama
Enable Express Forwarding on a security policy when your NGFWs are managed by
Panorama.
Log in to your Panorama web interface.
Select .
Select the appropriate
Device Group from the drop-down
menu where your security policy resides.
Select an existing security policy to modify or
Add a
new policy.
In the policy rule settings, locate and select the
Express
Forwarding checkbox.
Select
OK to close the policy settings, then
Commit the changes to Panorama.
Push the committed configuration to your target
NGFWs.
CLI
Configure Express Forwarding using the command-line interface for automation or
direct device access.
Access your firewall's command-line interface (CLI) or Panorama's CLI
configuration mode.
Enter configuration mode.
Enable express forwarding for a specific security policy.
set vsys <vsys-name> rulebase security rules <security-pol-name> option express-forwarding yes
(Optional) Disable express forwarding for a specific security policy.
set vsys <vsys-name> rulebase security rules <security-pol-name> option express-forwarding no
Commit the changes.