FortiOS 6.0.1 Maximum Values Table

The values in this table are the hard-coded maximum values. As such, they may not be practical limits for every situation and are not a promise of performance.

 

All objects in the maximum values table have either a global limit, which applies to the entire FortiGate configuration, or a VDOM limit, which applies only to a single VDOM. For objects that have only a VDOM limit, the global limit is the VDOM limit multiplied by the number of VDOMs for that unit. For example, the FortiGate 100D can have 10 VDOMs and has a VDOM limit of 256 DHCP servers. This means that the global limit is 2560.

By default, most FortiGate models support a maximum of 10 VDOMs in any combination of NAT/Route and Transparent operating modes. For FortiGate models 1000D and higher, a license key can be purchased to increase the maximum number.

If you wish to find out the complete maximum values for your FortiGate unit, use the following CLI command:

print tablesize

 


LEGEND
Black cells Objects with global limits.
Gray cells Objects with VDOM limits.
0 Objects with no hard limit, such as objects limited by system memory.
INT Objects that are limited by the number of available interfaces. This number includes both physical and virtual interfaces.
- Unsupported features.
* An exception is listed at the bottom of this field for the limit.


Models: Toggle All

FortiGate/FortiWiFi 30D series (excluding FortiGate Rugged)

FortiGate/FortiWiFi 30E series & FortiGate Rugged 30D series

FortiGate/FortiWiFi 50E series & FortiGate Rugged 60D series

FortiGate/FortiWiFi 60D & 60E series

FortiGate/FortiWiFi 70D, 80D, 80E, 90D, 90E series (including FortiGate Rugged)

FortiGate 100D, 140D, & 140E

FortiGate 100E

FortiGate 200D

FortiGate 200E

FortiGate 300D, 300E, 400D, 500D, & 500E series

FortiGate 600D

FortiGate 800D, & 900D

FortiGate 1000D & 1200D

FortiGate 1500D

FortiGate 2000E & 2500E

FortiGate 3000D, 3100D, & 3200D

FortiGate 3700D, 3800D, 3810D, 3815D, 3960E, & 3980E

FortiGate 5001D & 5001E

VM-Evaluation

VM0

VM1

VM2

VM4

VM8 & on demand VM platforms

OBJECT 30D series 30E series 50E series 60D & 60E series 70D, 80D, 80E, 90D, & 90E series 100D, 140D, & 140E 100E 200D 200E 300D, 300E, 400D, 500D, & 500E 600D 800D & 900D 1000D & 1200D 1500D & 1500DT 2000E & 2500E 3000D, 3100D, & 3200D 3700D, 3800D, 3810D, 3815D, 3960E, & 3980E 5100D, 5100E VMEV VM0 VM1 VM2 VM4 VM8 & on demand
  SYSTEM
Access profiles 8 8 8 16 16 16 16 16 16 16 16 16 64 64 64 64 64 64 8 16 16 16 16 64
Admin accounts 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 550 550 550 300 300 300 300 300 550
ARP Proxy 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
IP and MAC Binding 2000 2000 2000 2000 2000 10240 10240 10240 10240 10240 10240 10240 16834 16834 16834 16834 16834 16834 2000 10240 10240 10240 10240 16834
Certificates
CA 200 200 200 200 200 200 200 200 200 200 200 200 500 500 500 500 500 500 200 200 200 200 200 500
CRL 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Local 200 200 200 200 200 200 200 200 200 500 500 500 1000 1000 1000 1000 1000 1000 200 200 500 500 1000 1000
Explicit proxy Concurrent users 500 500 500 1000 1000 8000 8000 8000 8000 8000 8000 8000 16000 16000 16000 64000 64000 64000 500 8000 8000 16000 16000 64000
Addresses 1024 1024 1024 1024 1024 2048 2048 2048 2048 2048 2048 2048 8192 8192 8192 8192 8192 8192 1024 2048 2048 2048 2048 8192
Address groups 512 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 512 1024 1024 1024 1024 4096
Members per address group 300 300 300 300 300 300 300 300 300 300 300 300 1500 1500 1500 1500 1500 1500 300 300 300 300 300 1500
DHCP Address ranges per server 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Exclude ranges per server 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
Reserved addresses 200 200 200 200 200 200 200 200 200 200 200 200 5000 5000 5000 5000 5000 5000 200 200 200 200 200 5000
Servers 32 32 32 32 32 256 256 256 256 256 256 256 1024 1024 1024 4192 4192 4192 16 256 256 256 256 4192
Server options 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30
GRE tunnels 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Interfaces (VLAN + physical) NAT/Route mode 256* 256* 256 256 256 4096 4096 4096 4096 8192 8192 8192 16384 16384 16384 16384 16384 16384 256 4096 8192 8192 8192 16384
Transparent mode 254* 254* 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254
IPS URL filter DNS (IPv4) 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
IPS URL filter DNS (IPv4) 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
IPv6 prefix lists per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IPv6 tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
Static MAC Addresses 200 200 200 200 200 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 200 200 200 200 200 2000
Replacement messages Groups 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Images 8 8 8 8 8 16 16 16 16 16 16 16 31 31 31 31 31 31 31 16 16 16 16 31
SD-WAN Health checks 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000
Members 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Services 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000
Secondary IP addresses per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Session-TTL ports 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512
SIT tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
SNMP Communities 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Hosts per community 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Users 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
VDOM links INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
WAN Link Load Balance 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
WiFi MAC address list entries 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Zones 20 20 20 20 20 50 50 50 50 100 100 200 500 500 500 500 500 500 20 50 100 200 200 500
  ROUTER
Access lists Entries 32 32 32 32 32 100 100 100 100 100 100 100 100 100 100 100 100 100 32 100 100 100 100 100
Rules per entry 20 20 128 128 128 256 256 256 256 256 256 256 512 512 512 512 512 512 20 256 256 256 256 512
Authentication paths 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
BGP Aggregate addresses 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Confederation peers 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbors 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 1000 1000 1000 1000 1000 5000
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Routes 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Community lists 64 64 64 64 64 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 64 512 512 512 512 2048
Keychain Entries 16 16 16 16 16 16 16 16 16 16 16 16 100 100 100 100 100 100 16 16 16 16 16 100
Rules per entry 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
OSPF Areas 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Area ranges 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Distribute lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Filter lists 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbors 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Passive interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Summary addresses 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25
Virtual links 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Policy routes 250 250 250 250 250 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 250 512 512 512 512 2048
Prefix lists Entries 32 32 32 32 32 100 100 100 100 100 100 100 100 100 100 100 100 100 32 100 100 100 100 100
Rules per entry 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
RIP Distances 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Distribute lists 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Interfaces 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Neighbours 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Networks 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Offset lists 32 32 32 32 32 256 256 256 256 256 256 256 2048 2048 2048 2048 2048 2048 256 256 256 256 256 2048
Passive interfaces 256 256 256 256 256 300 300 300 300 300 300 300 300 300 300 300 300 300 256 300 300 300 300 300
Route Maps 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per map 20 20 20 20 20 50 50 50 50 50 50 50 50 50 50 100 100 100 20 50 50 50 50 100
Static routes 100 100 100 100 100 500 500 500 500 5000 10000 10000 10000 10000 10000 10000 10000 10000 100 500 5000 10000 10000 10000
Static routes (IPv6) 8 8 8 8 100 500 500 500 500 500 500 500 500 500 500 500 500 500 8 500 500 500 500 500
  FIREWALL & FIREWALL OBJECTS
Addresses Addresses 5000 5000 5000 5000 5000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 100000 200000 200000 5000 20000 20000 20000 20000 100000
Address groups 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 20000 20000 20000 20000 20000 20000 20000 2500 2500 2500 2500 2500 20000
Addresses per group 300 300 300 300 300 300 300 300 300 300 300 300 1500 1500 1500 1500 1500 1500 300 300 300 300 300 1500
Central SNAT map 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 10000 10000 10000 10000 10000 10000 256 1024 1024 1024 1024 10000
DNS translations 32 32 32 32 32 32 32 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 32 32 512 512 512 1024
IP addresses per FQDN list 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IP pools 512 512 512 512 512 512 512 512 512 1024 1024 2048 2048 2048 32768 32768 32768 32768 512 512 1024 2048 2048 32768
IPv6 Addresses 5000 5000 5000 5000 5000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 100000 200000 200000 5000 20000 20000 20000 20000 100000
Address groups 2500 2500 2500 2500 2500 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 2500 8192 8192 8192 8192 8192
Policies 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 5 10000 10000 10000 10000 100000
Multicast Addresses (IPv4) 512 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 512 1024 1024 1024 1024 4096
Addresses (IPv6) 512 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 512 1024 1024 1024 1024 4096
Policies (IPv4) 32 32 32 32 32 64 64 64 64 128 128 128 256 256 256 256 256 256 32 64 128 128 256 256
Policies (IPv6) 32 32 32 32 32 64 64 64 64 128 128 128 256 256 256 256 256 256 32 64 128 128 256 256
NAT46 Policies 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 5 10000 10000 10000 10000 100000
NAT64 Policies 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 5 10000 10000 10000 10000 100000
Policies Policies 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 200000 200000 200000 5 10000 10000 10000 10000 200000
Users/devices/groups per identity-based policy 100 100 100 100 100 500 500 500 500 500 500 500 800 800 800 800 800 800 100 500 500 500 500 800
Profile groups 32 32 32 32 32 32 32 32 32 500 500 20000 20000 20000 20000 20000 20000 20000 32 32 500 20000 20000 20000
Protocol options profiles 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 2 32 500 500 500 500
Proxy policies 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 200000 200000 200000 5 10000 10000 10000 10000 200000
Schedules One-time 256 256 256 256 256 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 256 1000 1000 1000 1000 5000
Recurring 256 256 256 256 256 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 1024 256 512 512 512 512 1024
Services Categories 200 200 200 200 200 500 500 500 500 500 500 500 5000 5000 5000 10000 10000 10000 200 500 500 500 500 10000
Groups 500 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1500 1500 1500 1500 1500 1500 500 1000 1000 1000 1000 1500
Members per group 300 300 300 300 300 300 300 300 300 300 300 300 300 1000 1000 1000 1000 1000 300 300 300 300 300 1000
Services 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 10240 10240 10240 10240 10240 1024 1024 1024 1024 4096 10240
Traffic shaping Per IP traffic shapers 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 32 32 500 500 500 500
Traffic shapers 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 32 32 500 500 500 500
Virtual IPs Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
IPv6 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
IPv6 virtual IP mapping 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 50 16384 16384 16384 16384 32768
Load balancing monitors 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 512 512 512 256 256 256 256 512 512
Load balancing virtual servers 128 128 128 128 128 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 50 512 512 512 512 2048
Members per group 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 1024 1024 1024 500 500 500 500 1024 1024
NAT46 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT46 virtual IP mapping 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 50 16384 16384 16384 16384 32768
NAT64 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT64 virtual IP mapping 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 50 16384 16384 16384 16384 32768
Real servers per virtual server 4 4 4 4 4 8 8 8 8 8 8 8 32 32 32 32 32 32 - 8 8 8 8 32
Virtual IP mapping (excluding load balance virtual servers) 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 50 16384 16384 16384 16384 32768
  SECURITY PROFILES
AntiVirus Content Type 10 10 10 10 10 10 10 10 10 1000 1000 1000 2000 2000 2000 2000 2000 2000 10 10 1000 1000 2000 2000
Profiles 10 10 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 10 32 500 500 500 500
Application control Custom signatures 1000 1000 1000 1000 1000 1000 1000 1000 1000 9000 9000 9000 9000 9000 9000 9000 9000 9000 1000 1000 1000 9000 9000 9000
Sensors 10 32 32 32 32 256 256 256 256 256 256 256 1000 1000 1000 1000 1000 1000 10 256 256 256 256 1000
CASI profiles 10 32 32 32 32 256 256 256 256 256 256 256 1000 1000 1000 1000 1000 1000 10 256 256 256 256 1000
Data leak prevention File patterns 200 200 200 200 200 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 12500 12500 12500 2 1000 1000 1000 1000 12500
Entries per file pattern 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
Fingerprint sensitivity levels 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Sensors 10 32 32 32 32 64 64 64 64 64 64 64 1000 1000 1000 1500 1500 1500 10 64 64 64 64 1500
Filters per sensor 100 100 100 100 100 2000 2000 2000 2000 2000 2000 2000 10000 10000 10000 50000 50000 50000 20 2000 2000 2000 2000 50000
FortiClient compliance profiles 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 512 512 512 512 512 2048
FortiClientEMS servers 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Intrusion prevention system Custom signatures 1000 1000 1000 1000 1000 1000 1000 1000 1000 9000 9000 9000 9000 9000 9000 9000 9000 9000 1000 1000 1000 9000 9000 9000
Sensors 10 32 32 32 32 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 10 64 64 64 64 1000
Vulnerability scan assets 200 200 200 200 200 1000 1000 1000 1000 2000 2000 2000 65535 65535 65535 65535 65535 65535 25 1000 2000 2000 2000 65535
Spam filter Banned words lists 10 10 10 10 10 10 10 10 10 1000 1000 1000 2000 2000 2000 2000 2000 2000 10 10 1000 1000 2000 2000
Banned word entries per list 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
Black/white lists 20 20 20 20 20 20 20 20 20 2000 2000 2000 4000 4000 2000 4000 4000 4000 20 20 2000 2000 4000 4000
Black/white list entries 40000 40000 40000 40000 40000 64000 64000 64000 64000 100000 100000 100000 500000 500000 500000 500000 500000 500000 40000 64000 100000 100000 500000 500000
DNS-based blackhole lists 10 10 10 10 10 10 10 10 10 1000 1000 1000 2000 2000 2000 2000 2000 2000 10 10 1000 1000 2000 2000
DNS-based blackhole list entries 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
MIME header lists 10 10 10 10 10 10 10 10 10 1000 1000 1000 2000 2000 2000 2000 2000 2000 10 10 1000 1000 2000 2000
MIME header list entries 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
Profiles 10 10 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 10 32 500 500 500 500
Trusted IP addresses lists 10 10 10 10 10 10 10 10 10 1000 1000 1000 2000 2000 2000 2000 2000 2000 10 10 1000 1000 2000 2000
Trusted IP addresses list entries 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
SSL/SSH profiles 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 4 32 500 500 500 500
Web filter Content block lists 10 10 10 10 10 10 10 10 10 10 10 1000 2000 2000 2000 2000 2000 2000 10 10 10 1000 1000 2000
Content block entries per list 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
Exempt word lists 10 10 10 10 10 10 10 10 10 1000 1000 1000 2000 2000 2000 2000 2000 2000 10 10 1000 1000 2000 2000
Exempt word entries per list 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
FortiGuard local categories 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52
FortiGuard local ratings 1000 1000 2000 2000 2000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 1000 12000 12000 12000 12000 12000
Overrides 10 10 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 500 10 200 400 400 400 400
Profile keyword matches 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
Profiles 10 10 32 32 32 32 512 32 512 20000 20000 20000 20000 20000 20000 20000 20000 20000 10 32 20000 20000 20000 20000
URL Filters 10 10 32 32 32 256 256 256 256 256 256 256 1000 1000 1000 1000 1000 1000 10 256 256 256 256 1000
URL filter entries (global limit) 40000 40000 40000 40000 40000 64000 64000 64000 64000 100000 100000 100000 500000 500000 500000 500000 500000 500000 40000 64000 100000 100000 500000 500000
URL filter entries (VDOM limit) 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 250000 250000 250000 250000 250000 250000 20000 32000 50000 50000 250000 250000
  VPN
IPsec Concentrators 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Manual key configurations 50 50 50 50 50 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 50 2000 2000 2000 2000 2000
Phase 1 (Interface mode) INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Phase 1 (Policy mode) 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 20000 20000 20000 40000 40000 40000 200 2000 2000 2000 2000 40000
Phase 2 (Interface mode) INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Phase 2 (Policy mode) 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 20000 20000 20000 40000 40000 40000 200 2000 2000 2000 2000 40000
Tunnels per concentrator 10 10 100 100 100 300 300 300 300 300 300 300 300 300 300 300 300 300 10 300 300 300 300 300
SSL Bookmarks per portal 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Bookmarks per user 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Portals 1 1 10 10 10 50 50 50 50 50 128 128 256 256 256 256 256 256 - 50 50 50 50 256
  USER & DEVICE
AD groups 256 256 256 256 256 256 256 256 256 1024 1024 1024 8192 8192 8192 8192 8192 8192 256 256 1024 1024 8192 8192
Devices 400 400 400 400 400 4000 4000 4000 4000 4000 4000 4000 16000 16000 40000 40000 40000 40000 10 4000 4000 4000 16000 40000
FortiTokens 500 500 500 500 500 5000 5000 5000 5000 5000 5000 5000 20000 20000 20000 20000 20000 20000 500 5000 5000 5000 20000 20000
FSSO polling entries 5 5 5 5 5 20 20 20 20 20 20 20 100 100 100 100 100 100 5 20 20 20 20 100
FSSO servers 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Guest users 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 1024 1024 1024 500 500 500 500 1024 1024
LDAP servers 10 10 10 10 10 16 16 16 16 16 16 16 64 64 64 64 64 64 10 16 16 16 16 64
Local users 20 50 500 500 500 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 20 1000 1000 1000 5000 5000
Managed FortiSwitch 8 8 8 8 8 24 24 24 24 48 64 64 128 128 128 300 300 300 8 8 8 24 64 300
Members per user group 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Peers 200 200 5000 5000 60000 60000 60000 60000 60000 60000 60000 60000 60000 60000 60000 60000 60000 60000 200 60000 60000 60000 60000 60000
Peer groups 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Peer group members 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000 50000
RADIUS Accounting servers per RADIUS server 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
Servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
TACACS+ servers 10 10 10 10 10 10 10 10   10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
User groups 100 100 100 100 100 500 500 500 500 500 500 500 800 800 800 800 800 800 100 500 500 500 500 800
  WAN OPTIMIZATION & CACHE
Authentication groups 16 16 16 16 16 32 32 32 32 64 64 64 128 128 128 128 128 128 16 32 64 64 128 128
Peers 32 32 32 32 32 64 64 64 64 128 128 128 256 256 256 256 256 256 32 64 128 128 256 256
Profiles 32 32 32 32 32 64 64 64 64 128 128 128 256 256 256 256 256 256 32 64 128 128 256 256
SSL servers 32 32 32 32 32 64 64 64 64 128 128 128 256 256 256 256 256 256 32 64 128 128 256 256
  WIRELESS CONTROLLER
Custom AP profiles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Custom AP profile MAC deny list entries 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Managed FortiAPs (Total / Tunnel Mode) 2 / 2 2 / 2 10 / 5 10 / 5* 32 / 16 64 / 32 64 / 32 128 / 64 128 / 64 512 / 256 1024 / 512 1024 / 512 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 1 / 1 64 / 32 64 / 32 512 / 256 512 / 256 4096 / 1024
MPSK 8 8 8 8 8 32 32 32 32 32 32 32 64 64 64 128 128 128 4 32 32 32 32 128
SSIDs 32 32 32 32 32 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 16 256 256 256 256 1024
SSID lists per FortiAP 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
UTM profiles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
WIDS profiles 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
  LOG & REPORT
Custom log fields per policy 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Reports Body items per layout 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Charts 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 256 256 256 320 320 320
Datasets 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 256 256 256 320 320 320
Fields per datasets 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Footers per page per layout 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Headers per page per layout 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Layouts 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 16 16 16 32 32 32
Mapping per chart 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8
Styles 128 128 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 128 128 128 256 256 256
Summaries 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 16 16 16 32 32 32
Themes 8 8 8 8 8 8 8 8 8 8 8 16 16 16 16 16 16 16 8 8 8 16 16 16
Threat Weight Application-control settings 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Geolocation-based settings 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Web-based settings 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96
 

 

Exceptions:

 

CHANGE LOG
June 5, 2018 Initial release.

 


 

 

Copyright© 2018 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., in the U.S. and other jurisdictions, and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other resultsmay vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet's General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet's internal lab tests. In no event does Fortinet make any commitment related to future deliverables, features, or development, and circumstances may change such that any forward-looking statements herin are not accurate. Fortinet disclaims in full any covenants, representations,and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.