0% found this document useful (0 votes)
46 views3 pages

FortiGate Maximum Values Overview

The Maximum Values Table outlines hard-coded limits for various objects in FortiGate configurations, distinguishing between global and VDOM limits. It specifies that the global limit for objects with only a VDOM limit is the VDOM limit multiplied by the number of VDOMs. The document also provides a CLI command for users to find complete maximum values for their specific FortiGate unit.

Uploaded by

Mobiwank
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
46 views3 pages

FortiGate Maximum Values Overview

The Maximum Values Table outlines hard-coded limits for various objects in FortiGate configurations, distinguishing between global and VDOM limits. It specifies that the global limit for objects with only a VDOM limit is the VDOM limit multiplied by the number of VDOMs. The document also provides a CLI command for users to find complete maximum values for their specific FortiGate unit.

Uploaded by

Mobiwank
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

About the Maximum Values Table

The values in this table are the hard-coded maximum values. As such, they may not
be practical limits for every situation and are not a promise of performance.

All objects in the maximum values table have either a global limit, which applies to the entire FortiGate configuration, or a VDOM limit, which applies only to a single VDOM. For objects that have only a VDOM limit, the global limit is the VDOM limit multiplied by the number of VDOMs for that unit. For example, the FortiGate60C can have 10 VDOMs
and has a VDOM limit of 32 DHCP servers. This means that the global limit is 320.

By default, most FortiGate models support a maximum of 10 VDOMs in any combination of NAT/Route and Transparent operating modes. For FortiGate models 3000 and higher, a license key can be purchased to increase the maximum number.

The Maximum Values Table contains the values for FortiOS 5.2.5. For more information, see the Change Log.

If you wish to find out the complete maximum values for your FortiGate unit, use the following CLI command:

print tablesize

LEGEND
Black cells Objects with global limits.
Gray cells Objects with VDOM limits.
0 Objects with no hard limit, such as objects limited by system memory.
Objects that are limited by the number of available interfaces. This number includes
INT
both physical and virtual interfaces.
- Unsupported features.
* An exception is listed at the bottom of this field for the limit.

Models: Toggle All

FortiGate VM (Evaluation Version) FortiGate 200B series FortiGate 800C & 900D FortiGate 3600C

FortiGate/FortiWiFi 20 series FortiGate 200D series FortiGate VM04 FortiGate 3810A

FortiGate/FortiWiFi 30 series FortiGate 300C, 300D, 310B-DC, 311B, 400D & 500D FortiGate 1000C, 1240B, & 1500D FortiGate 3810D

FortiGate/FortiWiFi 40C FortiGate 310B FortiGate 1000D FortiGate 3000D, 3100D, 3200D, 3700D, 3950B, 3951B, & VM08

FortiGate/FortiWiFi 60 series (including FortiGate Rugged) FortiGate VM01 FortiGate 1200D FortiGate VM & VM64

FortiGate/FortiWiFi 70D & 90 series FortiGate 600C & 600D FortiGate 3016B FortiGate 5001 series

FortiGate/FortiWiFi 80 series FortiGate 620B-DC FortiGate 3040B & 3140B FortiGate 5101C & FortiController 5902D

FortiGate 100 series (including FortiGate Rugged) FortiGate 620B & 621B FortiGate 3240C FortiSwitch 5203B

FortiGate VM00 FortiGate VM02

300C,
3000D,
300D,
1000C, 3100D, 3200D,
70D & 90 100 200B 200D 310B-DC, 600C & 620B & 800C & 3040B & VM 5001 5101C &
OBJECT VMEV 20 series 30 series 40C 60 series
series
80 series
series
VM00
series series 311B,
310B VM01
600D
620B-DC
621B
VM02
900D
VM04 1240B &
1500D
1000D 1200D 3016B
3140B
3240C 3600C 3810A 3810D 3700D,
3950B,3951B
& VM64 series 5902D
5203B

400D &
& VM08
500D

SYSTEM
Access profiles 8 8 8 8 8 8 8 16 16 16 16 16 16 16 16 16 16 16 16 16 64 64 64 64 64 64 64 64 64 64 64 64 64 64
Admin accounts 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 550 550 550 550 550
Proxy 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
ARP
Table size 2000 2000 2000 2000 2000 2000 2000 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834
Local 200 200 200 200 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Certificates CA 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 500
CRL 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Concurrent explicit proxy users 2000 - 500 500 1000* 1000* 1000 8000 500 8000 8000 8000 4000 1000 8000 8000 8000 8000 16000 16000 15000* 15000 15000 16000 16000 16000 16000 16000 32000 18000* 32000 32000 32000 32000
Address ranges
3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
per server
Exclude ranges
4 4 4 4 4 4 4 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
DHCP per server
Reserved
200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 5000 5000 500 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
addresses
Servers 16 32 32 32 32 32 32 256 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 4192 4192 4192 4192 4192
GRE tunnels INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Interfaces NAT/Route mode 256 256* 256* 256 256 256 256 4096 4096 4096 4096 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
(VLAN +
physical) Transparent mode 254 254* 254* 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254
IPS URL filter DNS 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
IPv6 prefix lists per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IPv6 tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
MAC address table size 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Replacement Groups 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
messages Images 7 7 7 7 7 7 7 15 15 15 15 15 15 15 15 15 15 15 15 15 30 30 30 30 30 30 30 30 30 30 30 30 30 30
Secondary IP addresses per
32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
interface
Session-TTL ports 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512
SIT tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
Communities 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Hosts per
SNMP 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
community
Users 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
VDOM links INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
WiFi MAC address list entries 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Zones 20 20 20 20 20 20 20 50 50 50 50 100 100 100 100 100 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 500
ROUTER
Entries 32 32 32 32 32 32 32 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Access lists
Rules per entry 20 20 20 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 512 512 512 512 512 512 512 512 512 512 512
Authentication paths 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Aggregate
0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
addresses
Confederation
0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
peers
BGP Neighbors 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Redistribution
100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
tables
Routes 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Community lists 64 64 64 64 64 64 64 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Entries 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Keychain
Rules per entry 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
Areas 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Area ranges 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Distribute lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Filter lists 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbours 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
OSPF Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Passive interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Redistribution
100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
tables
Summary
25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25
addresses
Virtual links 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Policy routes 250 250 250 250 250 250 250 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Entries 32 32 32 32 32 100 32 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Prefix lists
Rules per entry 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
Distances 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Distribute lists 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Interfaces 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Neighbours 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
RIP Networks 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Offset lists 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Passive interfaces 256 256 256 256 256 256 256 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
Redistribution
100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
tables
Maps 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Route
Rules per map 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
Static routes 100 100 100 100 100 100 100 500 500 500 500 5000 5000 500 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
Static routes (IPv6) 8 8 8 8 8 8 8 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
FIREWALL & FIREWALL OBJECTS
Addresses 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 40000 40000 40000 40000 40000 40000 100000 40000 40000 100000 100000 100000 100000 100000
Addresses per
Addresses 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500
group
Address groups 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 20000 2500 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000
Central NAT table entries 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
DNS translations 32 32 32 32 32 32 32 32 32 512 512 512 512 512 512 512 512 512 1024 512 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
IP addresses per FQDN list 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IP pools 512 512 512 512 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 2048 2048 2048 2048 2048 2048 2048 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
Addresses 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 40000 40000 40000 40000 40000 40000 100000 40000 40000 100000 100000 100000 100000 100000
IPv6 Address groups 2500 2500 2500 2500 2500 2500 2500 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Addresses 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096
Multicast
Policies 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
NAT46 Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
NAT64 Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Users/devices
Policies /groups per
100 100 100 100 100 100 100 500 500 500 500 500 500 500 500 500 500 500 500 500 800 800 800 800 800 800 800 800 800 800 800 800 800 800
identity-based
policy
Profile groups 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000
Protocol options profiles 2 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
One-time 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Schedules
Recurring 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Categories 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 5000 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000
Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1000 1000 1000 1000 500 1000 500 1000 1000 500
Services Members per
300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
group
Services 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 1024 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096
SSL/SSH/deep inspection
2 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
options
Per IP traffic
Traffic 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
shapers
shaping
Traffic shapers 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
IPv6 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
IPv6 virtual IP
50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
mapping
Load balancing
256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 256 512 512 512 512 512 512 512 512 512 512 512
monitors
Load balancing
50 128 128 128 128 128 128 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
virtual servers
Members per
500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 500 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
group

Virtual IPs NAT46 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT46 virtual IP
50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
mapping
NAT64 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT64 virtual IP
50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
mapping
Real servers per
- 4 4 4 4 4 4 8 8 8 8 8 8 8 8 8 8 8 8 8 32 32 32 32 32 32 32 32 32 32 32 32 32 32
virtual server
Virtual IP mapping
(excluding load
50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
balance virtual
servers)
SECURITY PROFILES
Content Type 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
AntiVirus
Profiles 10 10 10 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Application control sensors 10 10 10 32 32 32 32 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Entries per file
20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
pattern
File patterns 2 200 200 200 200 200 200 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 12500 12500 12500 12500 12500
Data leak
Filters per sensor 20 100 100 100 100 100 100 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 10000 10000 10000 10000 10000 10000 10000 10000 1000 50000 50000 50000 50000 50000
prevention
Fingerprint
128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
sensitivity levels
Sensors 10 10 10 32 32 32 32 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1500 1500 1500 1500 1500
Intrusion Custom signatures 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
prevention
system Sensors 10 10 10 32 32 32 32 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Vulnerability scan assets 25 200 200 200 200 200 200 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535
Banned word
20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
entries per list
Banned words lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Black/white list
40000 40000 40000 40000 40000 40000 40000 64000 64000 64000 64000 100000 100000 100000 100000 100000 100000 100000 100000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000
entries
Black/white lists 20 20 20 20 20 20 20 20 20 20 20 20 2000 2000 2000 2000 2000 2000 2000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000
DNS-based
blackhole list 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
entries
DNS-based
10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Spam filter blackhole lists
MIME header list
20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
entries
>MIME header
10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
lists
Profiles 10 10 10 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Trusted IP
addresses list 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
entries
Trusted IP
10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
addresses lists
Content block
20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
entries per list
Content block lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Exempt word
20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
entries per list
Exempt word lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
FortiGuard local
52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52
categories
FortiGuard local
Web filter 1000 1000 1000 2000 2000 2000 2000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000
ratings
FortiGuard
10 10 10 50 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 500 500 500
warnings
Overrides 10 10 10 50 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 500 500 500
Profile keyword
64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
matches
Profiles 10 10 10 32 32 32 32 32 32 32 32 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 2000 20000 20000 20000 20000 20000
URL Filters 10 10 10 10 10 10 10 32 32 32 32 32 32 32 32 32 32 32 32 32 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
URL filter entries 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
VPN
Concentrators 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Manual key
50 50 50 50 50 50 50 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
configurations
Phase 1 (Interface
INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
mode)
Phase 1 (Policy
200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 20000 20000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 40000 40000
IPsec mode)
Phase 2 (Interface
INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
mode)
Phase 2 (Policy
200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 20000 20000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 40000 40000
mode)
Tunnels per
10 10 10 100 100 100 100 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
concentrator
Bookmarks per
256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
portal
SSL Bookmarks per
128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
user
Portals - 1 1 1 10 10 10 50 50 50 50 50 50 50 50 50 50 50 50 50 256 256 256 256 256 256 256 256 256 256 256 256 256 256

USER & DEVICE

AD groups 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Devices 10 10 400 400 400 400 400 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 16000 16000 16000 16000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000 8000
Endpoint control profiles 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
FortiTokens 20 20 20 100 100 100 100 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
FSSO polling entries 5 5 5 5 5 5 5 20 20 20 20 20 20 20 20 20 20 20 20 20 100 100 100 100 100 100 100 100 100 100 100 100 100 100
FSSO servers 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Guest users 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 500 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
LDAP servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Local users 20 20 20 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Members per user group 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350
Peers 20 20 20 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Accounting
servers per 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
RADIUS RADIUS server
Servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
TACACS+ servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
User groups 100 100 100 100 100 100 100 500 500 500 500 500 500 500 500 500 500 500 500 500 800 800 800 800 800 800 800 800 800 800 800 800 800 800
WAN OPTIMIZATION & CACHE
Authentication groups 16 16 16 16 16 16 16 32 32 32 32 64 64 64 64 64 64 64 64 128 128 128 64 128 128 128 128 128 128 128 128 128 128 128
Peers 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
Profiles 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
SSL servers 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
WIRELESS CONTROLLER
Custom AP profiles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Custom AP profile MAC deny list
256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
entries
Managed FortiAPs (Total / 512 / 1024 / 512 / 512 / 512 / 1024 / 512 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 / 4069 /
1/1 - 2/2 10 / 5 10 / 5 32 / 16 32 / 16 64 / 32 64 / 32 64 / 32 128 / 64 512 / 256 64 / 32 4069 / 1024
Tunnel Mode) 256 512 256 256 256 512 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
SSIDs 16 32 32 32 32 32 32 256 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
SSID lists per FortiAP 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
WIDS profiles 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
LOG & REPORT
Custom log fields per policy 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Body items per
256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
layout
Charts 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320
Datasets 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320
Fields per
32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
datasets
Footers per page
2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Reports per layout
Headers per page
2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
per layout
Layouts 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Mapping per chart 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8
Styles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Summaries 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Themes 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Application-control
32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
settings
Threat Geolocation-based
10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Weight settings
Web-based
96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96
settings

* Exception: FortiGate 60C-SFP has a concurrrent explicit proxy users limit of 500.

* Exception: the following models have a concurrrent explicit proxy users limit of 500: FortiGate 90D, FortiGate 92D, and FortiWiFi 92D.

* Exception: FortiGate 1240B and FortiGate 1500D have a concurrent explicit proxy users limit of 16000.

* Exception: FortiGate 3950B, 3951B, and FortiGate-VM08 have a concurrent explicit proxy users limit of 32000.

* Exception: The VLAN limit for FortiGate 20 series is 5 VLANs per interface.

* Exception: The VLAN limit for FortiGate 30 series is 20 VLANs per interface.

CHANGE LOG
Dec 8, 2015 Initial release.
Dec 9, 2015 Added FortiGate 3200D, added exception for 3950B, 3951B, and VM08.
Jan 6, 2016 Corrected VLAN limit for FortiGate 30 series.

Copyright© 2016 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., in the U.S. and other jurisdictions, and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be
trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other resultsmay vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding
commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet's General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event,
only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet's internal lab tests. In no event does Fortinet make any commitment related to future deliverables, features, or
development, and circumstances may change such that any forward-looking statements herin are not accurate. Fortinet disclaims in full any covenants, representations,and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most
current version of the publication shall be applicable.

You might also like