Skip to main content
Dattatray
Explorer
October 17, 2024
Solved

Entry limit of Link Monitoring in FortiGate 400F

  • October 17, 2024
  • 2 replies
  • 1619 views

I have 400F device and on this device we have configured around 1000 site to site VPN tunnels in active passive mode. We need to configure 330 link monitoring entries. I am able to configure 256 entries after that getting an error reached maximum entries. How can we increase the limit of link monitoring entries. 

 

Best answer by saleha

Hi Dattatray,

Thank you for your inquiry. There are no options to increase beyond maximum value as this is a design limit. I would alternatively recommend considering sdwan configuration instead of link monitor which would be a migration project as the tunnel interfaces have to be not referenced in other config specially firewall policies before they can become sdwan members. On the plus side though sdwan offers the amount of health-checks entries you need according the max value table for 400F models and SDWAN offers more granular control and management of routing.

sdwan reference: https://docs.fortinet.com/document/fortigate/7.4.5/administration-guide/431448/sd-wan-overview

max value table: https://docs.fortinet.com/max-value-table

 

Thank you,

saleha

2 replies

saleha
Staff & Editor
salehaAnswer
Staff & Editor
October 17, 2024

Hi Dattatray,

Thank you for your inquiry. There are no options to increase beyond maximum value as this is a design limit. I would alternatively recommend considering sdwan configuration instead of link monitor which would be a migration project as the tunnel interfaces have to be not referenced in other config specially firewall policies before they can become sdwan members. On the plus side though sdwan offers the amount of health-checks entries you need according the max value table for 400F models and SDWAN offers more granular control and management of routing.

sdwan reference: https://docs.fortinet.com/document/fortigate/7.4.5/administration-guide/431448/sd-wan-overview

max value table: https://docs.fortinet.com/max-value-table

 

Thank you,

saleha

Dattatray
DattatrayAuthor
Explorer
October 21, 2024

Hi Saleha,

 

Thanks for your suggestion. We done the SDWAN configuration and it's working fine without any issue.

 

Thanks,

Dattatray

Toshi_Esumi
SuperUser
SuperUser
October 17, 2024

Another option is a routing protocol if the other end support any. We use BGP(eBGP) for about 1000 locations. Otherwise, it's time for adding another FGT.

Toshi