About the Maximum Values Table

 

 


The values in this table are the hard-coded maximum values. As such, they may not be practical limits for every situation and are not a promise of performance.

 

All objects in the maximum values table have either a global limit, which applies to the entire FortiGate configuration, or a VDOM limit, which applies only to a single VDOM. For objects that have only a VDOM limit, the global limit is the VDOM limit multiplied by the number of VDOMs for that unit. For example, the FortiGate60C can have 10 VDOMs and has a VDOM limit of 32 DHCP servers. This means that the global limit is 320.

By default, most FortiGate models support a maximum of 10 VDOMs in any combination of NAT/Route and Transparent operating modes. For FortiGate models 1000C and higher, a license key can be purchased to increase the maximum number.

The Maximum Values Table contains the values for FortiOS 5.2.7. For more information, see the Change Log.

If you wish to find out the complete maximum values for your FortiGate unit, use the following CLI command:

print tablesize

 

 


LEGEND
Black cells Objects with global limits.
Gray cells Objects with VDOM limits.
0 Objects with no hard limit, such as objects limited by system memory.
INT Objects that are limited by the number of available interfaces. This number includes both physical and virtual interfaces.
- Unsupported features.
* An exception is listed at the bottom of this field for the limit.


Models: Toggle All

FortiGate VM (Evaluation Version)

FortiGate/FortiWiFi 20 series

FortiGate/FortiWiFi 30 series

FortiGate/FortiWiFi 40C

FortiGate/FortiWiFi 60 series (including FortiGate Rugged)

FortiGate/FortiWiFi 70D & 90 series

FortiGate/FortiWiFi 80 series

FortiGate 100 series (including FortiGate Rugged)

FortiGate VM00

FortiGate 200B series

FortiGate 200D series

FortiGate 300C, 300D, 310B-DC, 311B, 400D & 500D

FortiGate 310B

FortiGate VM01

FortiGate 600C & 600D

FortiGate 620B-DC

FortiGate 620B & 621B

FortiGate VM02

FortiGate 800C, 800D, & 900D

FortiGate VM04

FortiGate 1000C, 1240B, 1500D, & 1500DT

FortiGate 1000D

FortiGate 1200D

FortiGate 3016B

FortiGate 3040B & 3140B

FortiGate 3240C

FortiGate 3600C

FortiGate 3810A

FortiGate 3810D

FortiGate 3000D, 3100D, 3200D, 3700D, 3815D, 3950B, 3951B, & VM08

FortiGate VM & VM64

FortiGate 5001 series

FortiGate 5101C & FortiController 5902D

FortiSwitch 5203B

OBJECT VMEV 20 series 30 series 40C 60 series 70D & 90 series 80 series 100 series VM00 200B series 200D series 300C, 300D, 310B-DC, 311B, 400D & 500D 310B VM01 600C & 600D 620B-DC 620B & 621B VM02 800C, 800D, & 900D VM04 1000C, 1240B, 1500D, & 1500DT 1000D 1200D 3016B 3040B & 3140B 3240C 3600C 3810A 3810D 3000D, 3100D, 3200D, 3700D, 3815D, 3950B,3951B & VM08 VM & VM64 5001 series 5101C & 5902D 5203B
  SYSTEM
Access profiles 8 8 8 8 8 8 8 16 16 16 16 16 16 16 16 16 16 16 16 16 64 64 64 64 64 64 64 64 64 64 64 64 64 64
Admin accounts 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 550 550 550 550 550
ARP Proxy 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Table size 2000 2000 2000 2000 2000 2000 2000 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834
Certificates Local 200 200 200 200 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
CA 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 500
CRL 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Concurrent explicit proxy users 2000 - 500 500 1000* 1000* 1000 8000 500 8000 8000 8000 4000 1000 8000 8000 8000 8000 16000 16000 15000* 15000 15000 16000 16000 16000 16000 16000 32000 18000* 32000 32000 32000 32000
DHCP Address ranges per server 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Exclude ranges per server 4 4 4 4 4 4 4 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Reserved addresses 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 5000 5000 500 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Servers 16 32 32 32 32 32 32 256 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 4192 4192 4192 4192 4192
GRE tunnels INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Interfaces (VLAN + physical) NAT/Route mode 256 256* 256* 256 256 256 256 4096 4096 4096 4096 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Transparent mode 254 254* 254* 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254
IPS URL filter DNS 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
IPv6 prefix lists per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IPv6 tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
MAC address table size 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Replacement messages Groups 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Images 7 7 7 7 7 7 7 15 15 15 15 15 15 15 15 15 15 15 15 15 30 30 30 30 30 30 30 30 30 30 30 30 30 30
Secondary IP addresses per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Session-TTL ports 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512
SIT tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
SNMP Communities 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Hosts per community 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Users 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
VDOM links INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
WiFi MAC address list entries 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Zones 20 20 20 20 20 20 20 50 50 50 50 100 100 100 100 100 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 500
  ROUTER
Access lists Entries 32 32 32 32 32 32 32 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per entry 20 20 20 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 512 512 512 512 512 512 512 512 512 512 512
Authentication paths 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
BGP Aggregate addresses 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Confederation peers 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbors 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Redistribution tables 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Routes 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Community lists 64 64 64 64 64 64 64 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Keychain Entries 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per entry 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
OSPF Areas 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Area ranges 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Distribute lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Filter lists 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbours 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Passive interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Redistribution tables 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Summary addresses 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25
Virtual links 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Policy routes 250 250 250 250 250 250 250 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Prefix lists Entries 32 32 32 32 32 100 32 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per entry 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
RIP Distances 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Distribute lists 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Interfaces 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Neighbours 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Networks 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Offset lists 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Passive interfaces 256 256 256 256 256 256 256 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
Redistribution tables 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Route Maps 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per map 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
Static routes 100 100 100 100 100 100 100 500 500 500 500 5000 5000 500 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
Static routes (IPv6) 8 8 8 8 8 8 8 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
  FIREWALL & FIREWALL OBJECTS
Addresses Addresses 5000 5000 5000 5000 5000 5000 5000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 40000 40000 40000 100000 40000 40000 100000 100000 100000 100000 100000
Addresses per group 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500 1500
Address groups 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 20000 2500 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000
Central NAT table entries 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
DNS translations 32 32 32 32 32 32 32 32 32 512 512 512 512 512 512 512 512 512 1024 512 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
IP addresses per FQDN list 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IP pools 512 512 512 512 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 2048 2048 2048 2048 2048 2048 2048 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
IPv6 Addresses 5000 5000 5000 5000 5000 5000 5000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 40000 40000 40000 100000 40000 40000 100000 100000 100000 100000 100000
Address groups 2500 2500 2500 2500 2500 2500 2500 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Multicast Addresses 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096
Policies 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
NAT46 Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
NAT64 Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Policies Policies 5 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Users/devices/groups per identity-based policy 100 100 100 100 100 100 100 500 500 500 500 500 500 500 500 500 500 500 500 500 800 800 800 800 800 800 800 800 800 800 800 800 800 800
Profile groups 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000
Protocol options profiles 2 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Schedules One-time 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Recurring 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Services Categories 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 5000 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000
Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1000 1000 1000 1000 500 1000 500 1000 1000 500
Members per group 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
Services 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 1024 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096
SSL/SSH/deep inspection options 2 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Traffic shaping Per IP traffic shapers 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Traffic shapers 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Virtual IPs Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
IPv6 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
IPv6 virtual IP mapping 50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
Load balancing monitors 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 256 512 512 512 512 512 512 512 512 512 512 512
Load balancing virtual servers 50 128 128 128 128 128 128 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Members per group 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 500 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
NAT46 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT46 virtual IP mapping 50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
NAT64 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT64 virtual IP mapping 50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
Real servers per virtual server - 4 4 4 4 4 4 8 8 8 8 8 8 8 8 8 8 8 8 8 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Virtual IP mapping (excluding load balance virtual servers) 50 512 512 512 512 512 512 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 16384 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
  SECURITY PROFILES
AntiVirus Content Type 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000  
Profiles 10 10 10 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Application control sensors 10 10 10 32 32 32 32 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Data leak prevention Entries per file pattern 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
File patterns 2 200 200 200 200 200 200 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 12500 12500 12500 12500 12500
Filters per sensor 20 100 100 100 100 100 100 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 10000 10000 10000 10000 10000 10000 10000 10000 1000 50000 50000 50000 50000 50000
Fingerprint sensitivity levels 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Sensors 10 10 10 32 32 32 32 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1500 1500 1500 1500 1500
Intrusion prevention system Custom signatures 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Sensors 10 10 10 32 32 32 32 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Vulnerability scan assets 25 200 200 200 200 200 200 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535
Spam filter Banned word entries per list 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
Banned words lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Black/white list entries 40000 40000 40000 40000 40000 40000 40000 64000 64000 64000 64000 100000 100000 100000 100000 100000 100000 100000 100000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000 500000
Black/white lists 20 20 20 20 20 20 20 20 20 20 20 20 2000 2000 2000 2000 2000 2000 2000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000
DNS-based blackhole list entries 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
DNS-based blackhole lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
MIME header list entries 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
>MIME header lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Profiles 10 10 10 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Trusted IP addresses list entries 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
Trusted IP addresses lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Web filter Content block entries per list 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
Content block lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Exempt word entries per list 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
Exempt word lists 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 1000 1000 1000 2000 2000 2000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
FortiGuard local categories 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52
FortiGuard local ratings 1000 1000 1000 2000 2000 2000 2000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000
FortiGuard warnings 10 10 10 50 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 500 500 500
Overrides 10 10 10 50 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 500 500 500
Profile keyword matches 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
Profiles 10 10 10 32 32 32 32 32 32 32 32 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 2000 20000 20000 20000 20000 20000
URL Filters 10 10 10 10 10 10 10 32 32 32 32 32 32 32 32 32 32 32 32 32 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
URL filter entries 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
  VPN
IPsec Concentrators 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Manual key configurations 50 50 50 50 50 50 50 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Phase 1 (Interface mode) INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Phase 1 (Policy mode) 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 20000 20000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 40000 40000
Phase 2 (Interface mode) INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Phase 2 (Policy mode) 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 20000 20000 20000 20000 20000 20000 20000 20000 20000 40000 40000 40000 40000 40000
Tunnels per concentrator 10 10 10 100 100 100 100 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
SSL Bookmarks per portal 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Bookmarks per user 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Portals - 1 1 1 10 10 10 50 50 50 50 50 50 50 128 50 50 50 128 * 50 256 256 256 256 256 256 256 256 256 256 256 256 256 256

  USER & DEVICE

AD groups 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Devices 10 10 400 400 400 400 400 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 4000 16000 16000 16000 16000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000 8000
Endpoint control profiles 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
FortiTokens 20 20 20 100 100 100 100 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
FSSO polling entries 5 5 5 5 5 5 5 20 20 20 20 20 20 20 20 20 20 20 20 20 100 100 100 100 100 100 100 100 100 100 100 100 100 100
FSSO servers 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Guest users 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 500 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
LDAP servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Local users 20 20 20 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Members per user group 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350
Peers 20 20 20 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
RADIUS Accounting servers per RADIUS server 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
Servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
TACACS+ servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
User groups 100 100 100 100 100 100 100 500 500 500 500 500 500 500 500 500 500 500 500 500 800 800 800 800 800 800 800 800 800 800 800 800 800 800
  WAN OPTIMIZATION & CACHE
Authentication groups 16 16 16 16 16 16 16 32 32 32 32 64 64 64 64 64 64 64 64 128 128 128 64 128 128 128 128 128 128 128 128 128 128 128
Peers 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
Profiles 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
SSL servers 32 32 32 32 32 32 32 64 64 64 64 128 128 128 128 128 128 128 128 256 256 256 128 256 256 256 256 256 256 256 256 256 256 256
  WIRELESS CONTROLLER
Custom AP profiles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Custom AP profile MAC deny list entries 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Managed FortiAPs (Total / Tunnel Mode) 1 / 1 - 2 / 2 10 / 5 10 / 5 32 / 16 32 / 16 64 / 32 64 / 32 64 / 32 128 / 64 512 / 256 512 / 256 64 / 32 1024 / 512 512 / 256 512 / 256 512 / 256 1024 / 512 512 / 256 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024 4096 / 1024
SSIDs 16 32 32 32 32 32 32 256 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
SSID lists per FortiAP 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
WIDS profiles 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
  LOG & REPORT
Custom log fields per policy 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Reports Body items per layout 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Charts 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320
Datasets 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320
Fields per datasets 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Footers per page per layout 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Headers per page per layout 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Layouts 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Mapping per chart 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8
Styles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Summaries 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Themes 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Threat Weight Application-control settings 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Geolocation-based settings 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Web-based settings 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96

 

* Exception: FortiGate 60C-SFP has a concurrrent explicit proxy users limit of 500.

* Exception: the following models have a concurrrent explicit proxy users limit of 500: FortiGate 90D, FortiGate 92D, and FortiWiFi 92D.

* Exception: FortiGate 1240B and FortiGate 1500D have a concurrent explicit proxy users limit of 16000.

* Exception: FortiGate 3950B, 3951B, and FortiGate-VM08 have a concurrent explicit proxy users limit of 32000.

* Exception: The VLAN limit for FortiGate 20 series is 5 VLANs per interface.

* Exception: The VLAN limit for FortiGate 30 series is 20 VLANs per interface.

* Exception: FortiGate 800D has a SSL VPN Portal limit of 50.

 

 

CHANGE LOG
Apr 14, 2016 Initial release.

 


 

 

Copyright© 2016 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., in the U.S. and other jurisdictions, and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other resultsmay vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet's General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet's internal lab tests. In no event does Fortinet make any commitment related to future deliverables, features, or development, and circumstances may change such that any forward-looking statements herin are not accurate. Fortinet disclaims in full any covenants, representations,and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.