Fortinet builds purpose-designed Application-Specific Integrated Circuits, or ASICs, into FortiGate firewalls to accelerate networking and cybersecurity workloads that would otherwise consume resources on a general-purpose CPU. Fortinet refers to these chips collectively as Security Processing Units, or SPUs.
Rather than forcing the main processor to handle every packet, encryption operation, security inspection and forwarding decision in software, FortiOS can offload supported workloads to specialized hardware designed specifically for those operations. Fortinet currently organizes this acceleration architecture around Network Processors, Content Processors and integrated Security Processors.
The Network Processor, particularly the NP7 family, handles high-speed packet and network processing. NP7 operates in the traffic path and accelerates workloads including IPv4 and IPv6 forwarding, unicast and multicast traffic, IPsec processing, address translation, VXLAN termination, policy enforcement and hardware logging. Fortinet’s FortiOS 8.0 documentation describes NP7 and NP7Lite as fast-path processors that offload eligible communication sessions from the FortiGate CPU.
NP7Lite provides a lower-capacity implementation for systems that do not require the full scale of NP7, allowing the same general hardware-offload strategy to extend into smaller appliances.
The Content Processor, or CP, specializes in computationally intensive security operations. Fortinet has historically deployed processors such as CP9 and its Lite variants, while current FortiOS 8.0 documentation also includes the newer CP10.
CP10 increases inspection capability substantially: Fortinet documents up to 20 Gbps of IPSA processing throughput, twice that of CP9, while supporting a rule database six times larger. Content processors operate as co-processors rather than replacements for the main CPU, allowing FortiOS to offload supported security workloads to dedicated silicon and preserve CPU resources for other system functions.
Fortinet’s Security Processor 5, or SP5, takes the concept further by combining major processing functions into a System-on-a-Chip architecture. Fortinet describes SP5 as its fifth-generation security processor, integrating network and content-processing capabilities while targeting better performance, lower power requirements and smaller hardware footprints.
A current example is the FortiGate 120G/121G architecture, where Fortinet identifies the SOC5, also called SP5, as incorporating an SOC5 CPU, NP7Lite network processing and CP10 content processing. This integration allows smaller and midrange FortiGate appliances to obtain specialized hardware acceleration without requiring the same collection of discrete processors found in some larger platforms.
The important architectural concept is therefore CPU + specialized hardware offload. FortiOS remains responsible for operating the firewall and determining how traffic is processed, while supported workloads can be redirected to ASIC hardware designed to execute them efficiently. A simplified FortiGate data path can be viewed as network interfaces → network processor → security/content processing → forwarding, with the CPU retaining control over workloads that cannot or should not use the accelerated path.
The exact processor arrangement varies considerably by FortiGate model; higher-end systems can contain dedicated NP7 processors while newer integrated systems can use SP5/SOC5 implementations.
This hardware architecture matters most when a firewall must inspect enormous quantities of traffic without turning security itself into a bottleneck. Hardware acceleration can improve firewall throughput, IPsec VPN processing, session handling, encrypted-traffic inspection and threat-protection performance while reducing the amount of work assigned to the general-purpose CPU.
Fortinet continues to rely on this model in its newest hardware: in 2026, the company introduced FortiGate 3500G and 400G systems powered by NP7 and SP5 processors alongside FortiOS 8.0, showing that proprietary ASIC acceleration remains central to the FortiGate platform from enterprise edges to high-performance data-center environments.
Fortinet ASIC Architecture at a Glance
NP7 — Network Processor
High-speed packet forwarding, firewall acceleration, IPsec, NAT, VXLAN and other network-layer operations.
NP7Lite — Lightweight Network Processor
Lower-capacity NP7 implementation used in integrated and smaller FortiGate platforms while retaining most NP7 acceleration capabilities.
CP9 — Content Processor
Dedicated co-processor for resource-intensive security and content-processing workloads.
CP10 — Newer Content Processor
Current-generation content accelerator documented in FortiOS 8.0, offering increased inspection performance and a substantially larger rule database than CP9.
SP5 / SOC5 — Security Processor
Fifth-generation integrated Fortinet ASIC architecture capable of combining CPU, networking and security-processing functionality within a System-on-a-Chip implementation.
FortiOS — Operating System and Control Layer
Controls the firewall and determines which eligible network and security workloads can be accelerated through Fortinet’s specialized processing hardware.
Simplified FortiGate Hardware Flow
Ethernet / Fiber Interface
↓
NP7 / NP7Lite
Packet and network acceleration
↓
CP9 / CP10 / SP5
Security and content acceleration
↓
FortiOS + CPU
Policy, management and system control
↓
Forwarded Network Traffic
The exact path varies by FortiGate model and traffic type, but the central principle remains the same: move repetitive, high-volume networking and security operations from general-purpose software into hardware specifically designed to perform them.
BitcoinVersus.Tech Editor’s Note:
We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support to help further secure the integrity of our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment