Sophos Firewall uses FastTrack to offload known not-dangerous traffic to a faster path, in the new XGS hardware models, this traffic is pushed to the new Xstream Flow Processor:
“In the XG series we used a virtual FastPath that was processed by the CPU. The XGS series includes an Xstream Flow Processor that sits between the physical ports and the CPU, with a PCIe (PCI Express) interconnect between them. The Xstream Flow Processor handles the traffic that is offloaded to the FastPath reducing the load on the CPU for other tasks that cannot be offloaded. “
If you want to check if traffic is being offloaded to the FastPath on an XGS series device, you would start by checking if firewall acceleration is enabled on the console with the command:
console> system firewall-acceleration show
You can also use the system firewall-acceleration command to enable and disable the FastPath.
To check a specific connection, you can use conntrack on the advanced shell.

Note:
# usfp_table_print.sh worker_sys_cnt
