About the Maximum Values Table


The values in this table are the hard-coded maximum values. As such, they may not be practical limits for every situation and are not a promise of performance.

All objects in the maximum values table have either a global limit, which applies to the entire FortiGate configuration, or a VDOM limit, which applies only to a single VDOM. For objects that have only a VDOM limit, the global limit is the VDOM limit multiplied by the number of VDOMs for that unit. For example, the FortiGate-60C can have 10 VDOMs and has a VDOM limit of 32 DHCP servers. This means that the global limit is 320.

By default, most FortiGate models support a maximum of 10 VDOMs in any combination of NAT/Route and Transparent operating modes. For FortiGate models 3000 and higher, a license key can be purchased to increase the maximum number.



The Maximum Values Table has been updated with values for FortiOS 5.0.6. For more information, see the Change Log.

For information about which features are supported by a FortiGate model, see the Feature/Platform Matrix.

LEGEND
Black cells Objects with global limits
Gray cells Objects with VDOM limits
0 Objects with no hard limit, such as objects limited by system memory
INT Objects that are limited by the number of available interfaces
- Unsupported feature


Models: Toggle All

FortiGate-VM (Evaluation Version)

FortiGate 20 series

FortiGate 30 series

FortiGate-40C

FortiGate 60C series

FortiGate-60D

FortiGate 80 series

FortiGate 90 series

FortiGate Rugged-100C

FortiGate 100-140 series

FortiGate-VM00

FortiGate 200-240 series

FortiGate-300C

FortiGate-310B

FortiGate-VM01

FortiGate-311B

FortiGate-600C

FortiGate-620B-DC

FortiGate-620B & 621B

FortiGate-VM02

FortiGate-800C

FortiGate-VM04

FortiGate-1000C & 1240B

FortiGate-1500D

FortiGate-3016B

FortiGate-3040B & 3140B

FortiGate-3240C

FortiGate-3600C

FortiGate-3810A

FortiGate-3700D, 3950B, 3951B, & VM08

FortiGate-VM, VM64, & VM64-XEN

FortiGate 5001 series

FortiGate-5101C

FortiSwitch-5203B

OBJECT FG-VMEV FG-20 FG-30 FG-40C FG-60C FG-60D FG-80 FG-90 FGR-100C FG-100-140 FG-VM00 FG-200-240 FG-300C FG-310B FG-VM01 FG-311B FG-600C FG-620B-DC FG-620B-621B FG-VM02 FG-800C FG-VM04 FG-1000C-1240B FG-1500D FG-3016B FG-3040B-3140B FG-3240C FG-3600C FG-3810A FG-3950B-3951B & VM08 FG-VM, VM64, & VM64-XEN FG-5001 FG-5101C FS-5203B
  SYSTEM
Access profiles 8 8 8 8 8 8 8 8 8 16 16 16 16 16 16 16 16 16 16 16 16 16 64 64 64 64 64 64 64 64 64 64 64 64
Admin accounts 300 300 300 300 300 300 300 300 300 300 300 300 16 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 550 550 550 550 550
ARP Proxy 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Table size 2000 2000 2000 2000 2000 2000 2000 2000 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 10240 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834 16834
Certificates Local 200 200 200 200 200 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
CA 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
CRL 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Concurrent explicit proxy users 2000 - - 1000 1000 500 1000 500 2000 2000 18000 3000 4000 4000 18000 4000 8000 8000 8000 18000 12000 18000 15000 15000 15000 15000 12000 15000 15000 18000 18000 18000 18000 18000
DHCP Address ranges per server 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Exclude ranges per server 4 4 4 4 4 4 4 4 4 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Reserved addresses 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Servers 16 32 32 32 32 32 32 32 256 256 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 4192 4192 4192 4192 4192
GRE tunnels INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Interfaces NAT/Route mode 256 256 256 256 256 256 256 256 256 4096 4096 4096 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Transparent mode 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254 254
IPS URL filter DNS 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
IPv6 prefix lists per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
IPv6 tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
MAC address table size 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Replacement messages Groups 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
Images 7 7 7 7 7 7 7 7 15 15 15 15 15 15 15 15 15 15 15 15 15 15 30 30 30 30 30 30 30 30 30 30 30 30
Secondary IP addresses per interface 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Session-TTL ports 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512 512
SIT tunnels 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
SNMP Communities 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3
Hosts per community 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
Users 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
VDOM links INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
WiFi MAC address list entries 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Zones 20 20 20 20 20 20 20 20 20 50 50 50 100 100 100 100 100 100 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500
  ROUTER
Access lists Entries 32 32 32 32 32 32 32 32 32 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per entry 20 20 20 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 512 512 512 512 512 512 512 512 512
Authentication paths 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
BGP Aggregate addresses 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Confederation peers 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbors 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Redistribution tables 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Routes 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Community lists 64 64 64 64 64 64 64 64 512 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Keychain Entries 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 100 100 100 100 100 100 100 100 100 100 100 100
Rules per entry 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
OSPF Areas 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Area ranges 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Distribute lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Filter lists 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Neighbours 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Networks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Passive interfaces 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Redistribution tables 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Summary addresses 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25 25
Virtual links 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
Policy routes 100 100 100 100 100 100 100 100 100 100 100 100 250 250 250 250 250 250 250 250 250 250 250 250 250 2048 2048 2048 2048 2048 2048 2048 2048 2048
Prefix lists Entries 32 32 32 32 32 32 32 32 32 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per entry 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
RIP Distances 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Distribute lists 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Interfaces 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Neighbours 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Networks 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Offset lists 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Passive interfaces 256 256 256 256 256 256 256 256 256 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
Redistribution tables 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Route Maps 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100
Rules per map 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
Static routes 100 100 100 100 100 100 100 100 100 500 500 500 5000 5000 500 500 10000 500 500 500 10000 500 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
Static routes (IPv6) 8 8 8 8 8 8 8 8 8 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
  FIREWALL & FIREWALL OBJECTS
Addresses Addresses 5000 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000
Addresses per group 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 1000 300 300 1000 1000 1000
Address groups 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 2500 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Central NAT table entries 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
DNS translations 32 32 32 32 32 32 32 32 32 32 32 512 512 512 512 512 512 512 512 512 1024 512 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
IP pools 512 512 512 512 512 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 1024 2048 2048 2048 2048 2048 2048 32768 32768 32768 32768 32768 32768 32768 32768 32768 32768
IPv6 Addresses 5000 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000 40000
Address groups 2500 2500 2500 2500 2500 2500 2500 2500 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Policies 5 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Multicast Addresses 512 512 512 512 512 512 512 512 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096
Policies 32 32 32 32 32 32 32 32 32 64 64 64 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256
NAT46 Policies 5 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
NAT64 Policies 5 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Policies Policies 5 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000 100000
Users/devices/groups per identity-based policy 100 100 100 100 100 100 100 100 500 500 500 500 500 500 500 500 500 500 500 500 500 500 800 800 800 800 800 800 800 800 800 800 800 800
Profile groups 32 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000
Protocol options profiles 2 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Schedules One-time 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Recurring 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Services Categories 200 200 200 200 200 200 200 200 500 500 500 500 500 500 500 500 500 500 500 500 500 500 5000 5000 5000 5000 5000 5000 5000 10000 10000 10000 10000 10000
Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1000 1000 500 500 1000 1000 500 1000 500 1000
Members per group 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
Services 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096 4096
SSL/SSH/deep inspection options 2 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Traffic shaping Per IP traffic shapers 32 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Traffic shapers 32 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Virtual IPs Groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Load balancing monitors 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 512 512 512 512 512 512 512 512 512 512 512 512 512
Load balancing virtual servers 50 128 128 128 128 128 128 128 512 512 512 512 512 512 512 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048
Members per group 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
NAT46 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT46 virtual IP mapping 50 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
NAT64 groups 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
NAT64 virtual IP mapping 50 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
Real servers per virtual server - 4 4 4 4 4 4 4 8 8 8 8 8 8 8 8 8 8 8 8 8 8 32 32 32 32 32 32 32 32 32 32 32 32
Virtual IP mapping (excluding load balance virtual servers) 50 512 512 512 512 512 512 512 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 2048 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
  SECURITY PROFILES
AntiVirus profiles 2 32 32 32 32 32 32 32 32 32 32 32 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Application control sensors 10 10 10 10 10 10 10 10 64 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Client reputation geographic locations 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Data leak prevention Entries per file pattern 20000 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
File patterns 2 200 200 200 200 200 200 200 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 12500 12500 12500 12500 12500
Filters per sensor 20 100 100 100 100 100 100 100 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 10000 10000 10000 10000 10000 10000 10000 50000 50000 50000 50000 50000
Fingerprint sensitivity levels 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Sensors 2 25 25 25 25 25 25 25 64 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1500 1500 1500 1500 1500
Intrusion prevention system Custom signatures 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Sensors 10 10 10 10 10 10 10 10 64 64 64 64 64 64 64 64 64 64 64 64 64 64 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000
Vulnerability scan assets 25 200 200 200 200 200 200 200 200 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535 65535
Web filter Content block entries per list 20000 20000 20000 20000 20000 20000 20000 20000 32000 32000 32000 32000 50000 50000 50000 50000 50000 50000 50000 50000 50000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000 250000
Content block lists 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 1000 1000 1000 1000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
FortiGuard local categories 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52 52
FortiGuard local ratings 1000 1000 1000 2000 2000 2000 2000 2000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000 12000
FortiGuard warnings 10 10 10 50 50 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 500 500 500
Overrides 10 10 10 50 50 50 50 50 200 200 200 200 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 400 500 500 500
Profile keyword matches 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64 64
Profiles 4 32 32 32 32 32 32 32 32 32 32 32 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000 20000
Regex URL filter entries per list 100 100 100 1000 1000 1000 1000 1000 4000 4000 4000 4000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 20000 20000 20000
  VPN
IPsec Concentrators 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500
Manual key configurations 50 50 50 50 50 50 50 50 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000
Phase 1 (Interface mode) INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Phase 1 (Policy mode) 200 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
Phase 2 (Interface mode) INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT INT
Phase 2 (Policy mode) 200 200 200 200 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000 10000
Tunnels per concentrator 10 10 10 100 100 100 100 100 160 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300 300
SSL Bookmarks per portal 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Bookmarks per user 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Portals - 1 1 1 10 10 10 10 50 50 50 50 50 50 50 50 50 50 50 50 50 50 256 256 256 256 256 256 256 256 256 256 256 256
  USER & DEVICE
AD groups 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192 8192
Devices - 10 10 10 200 200 200 200 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 2000 8000 8000 8000 8000 8000 8000 8000 8000 8000 8000 8000 8000
Endpoint control profiles 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
FortiTokens 20 20 20 100 100 100 100 100 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
FSSO polling entries 5 5 5 5 5 5 5 5 20 20 20 20 20 20 20 20 20 20 20 20 20 20 100 100 100 100 100 100 100 100 100 100 100 100
FSSO servers 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Guest users 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 500 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
LDAP servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
Local users 20 20 20 500 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
Members per user group 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350 350
Peers 20 20 20 500 500 500 500 500 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 1000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000 5000
RADIUS Accounting servers per RADIUS server 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4
Servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
SMS providers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
TACACS+ servers 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10 10
User groups 100 100 100 100 100 100 100 100 500 500 500 500 500 500 500 500 500 500 500 500 500 500 800 800 800 800 800 800 800 800 800 800 800 800
  WAN OPTIMIZATION & CACHE
Authentication groups 16 16 16 16 16 16 16 16 16 32 32 32 64 64 64 64 64 64 64 64 64 128 128 128 128 128 128 128 128 128 128 128 128 128
Peers 32 32 32 32 32 32 32 32 32 64 64 64 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256
Profiles 32 32 32 32 32 32 32 32 32 64 64 64 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256
SSL servers 32 32 32 32 32 32 32 32 32 64 64 64 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256
Web cache exempt lists 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
  WIRELESS CONTROLLER
Custom AP profiles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128
Custom AP profile MAC deny list entries 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Managed FortiAPs (Total / Tunnel Mode) 1 / 1 - 2 / 2 10 / 5 10 / 5 10 / 5 32 / 16 32 / 16 64 / 32 64 / 32 64 / 32 64 / 32 512 / 256 512 / 256 64 / 32 512 / 256 1024 / 512 512 / 256 512 / 256 512 / 256 1024 / 512 512 / 256 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024 4069 / 1024
SSIDs 16 32 32 32 32 32 32 32 256 256 256 256 256 256 256 256 256 256 256 256 256 256 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024 1024
SSID lists per FortiAP 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
  LOG & REPORT
Custom log fields per policy 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5
Log traffic filter rules 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50 50
Reports
Body items per layout 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Charts 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320
Datasets 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320 320
Fields per datasets 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Footers per page per layout 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Headers per page per layout 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2
Layouts 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Mapping per chart 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8
Styles 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 128 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256 256
Summaries 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
Themes 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16



CHANGE LOG
May 23, 2014. Changed value for interfaces in Transparent mode. Added note about the max values. Combined values for Managed AP units and changed to Global limit.
Mar. 14, 2014 Added separate column for FortiGate 30D series and updated number of managed FortiAPs.
Mar. 13, 2014 Increased Static Route limit for FortiGate-620B-DC, FortiGate-620B, FortiGate-621B, FortiGate-VM02, and FortiGate-VM04.
Feb. 27, 2014 Increased Static Route limit for FortiGate-600C and FortiGate-800C. Created a separate column for FortiGate-30D Series and increased limit for managed FortiAP units.
Feb. 17, 2014 Changed Transparent mode interfaces limit to a VDOM limit.
Feb. 11, 2014 Added FortiGate models 1500D and 3700D.
Jan. 28, 2014 Added FSSO polling entries.
Nov. 20, 2013 Changed GRE tunnels, VDOM Links, IPsec VPN Phase 1 (Interface Mode), and IPsec VPN Phase 2 (Interface Mode) value to INT (limited by number of available interfaces).
Nov. 11, 2013 Added "Concurrent explicit proxy users." Updates throughout to bring up to date for FortiOS 5.0.5.