Technical Tip: Configuring VDOM-Based Session Limits for Customers on FortiGate 6000/7000 Chassis
| Description | This article describes how to configure a VDOM-based session limit for customers on the FortiGate 6000/7000 chassis. It also describes how the session limit is calculated across FPM modules. |
| Scope | FortiGate 6000 Series. FortiGate 7000 Series. |
| Solution | VDOM-based session limit could be configured as below on the FortiGate 6000/7000 as well:
The value configured here limits the concurrent forward session count. It is calculated separately for each FPM. In other words, each FPM is limited to the configured number of sessions.
Expectation sessions are counted for this setting. If the session count reaches the limit, then expectation session packets also would be dropped.
If the session limit is reached, FortiGate would send a 'VDOM resource limit exceeded' event log. New session packets would also be dropped, but FortiGate does not go create a log separately for it.
Notes:
|