Skip to main content
New Member
June 27, 2026
Question

FortiManager install fails with "firewall policy table limit... global limit is 3" despite target FortiGate having 7+ policies configured locally

  • June 27, 2026
  • 2 replies
  • 48 views

Environment:

  • FortiManager 7.6.1
  • FortiGate-VM64-KVM, FortiOS 7.2.0 build1157, Evaluation License (15-day)
  • ADOM version 7.2

Issue:
When installing a Policy Package from FortiManager to a managed FortiGate, the install fails with:

 

 

post_vdom copy error::(errcode)3 - max entry. object: firewall policy. detail: global limit. solution: limit is 3

This strongly implies a hard cap of 3 firewall policies enforced during the FMG→device install process.

However, this is demonstrably NOT a device-side limitation. Running show firewall policy directly on the same FortiGate via console/SSH shows 7 policies already present and fully functional, created locally without any issue:

 

 

[paste your 7-policy output here]

This proves the FortiGate itself accepts well more than 3 policies. The limit is only encountered when FortiManager performs the install — meaning the restriction lives somewhere in FortiManager's install/validation logic (or possibly an ADOM/device-DB setting), not in the FortiGate's own firewall policy table or its evaluation license.

Questions for the community/Fortinet:

  1. Is this a known FortiManager-side validation rule tied to ADOM version 7.2, or to the evaluation-licensed VM specifically?
  2. Is there a setting (ADOM, device profile, or system global) that artificially caps the policy count during install, separate from the device's actual firewall policy table limit?
  3. Is this expected/documented behavior anywhere, since it does not appear in the standard "VM evaluation license limitations" documentation (which describes a 3-interface/3-route/3-policy cap that clearly isn't being enforced on the device itself in this case)?

Any insight appreciated — this is currently blocking a hands-on FortiManager/SD-WAN Overlay Orchestration lab build.

2 replies

Stephen_G
Staff & Editor
Staff & Editor
June 30, 2026

Hi xiaurrehman143,

 

Thanks for using Fortinet Community forums. We’ll look to get you an answer or help. 

 

Have a nice day,

Stephen_G - Fortinet Community Team
iyotov
Staff
Staff
July 2, 2026

If the FortiGate is fine with 7 policies, then this is likely a FortiManager issue with the table limits for the particular VM license type (platform type).
These are very old versions though. So, if you don’t have any particular reason to use a 4 years old FOS firmware and 2 years old FortiManager version, please try if the issue persists in the latest patches of your selected versions. That’s 7.6.7 for FortiManager and 7.2.13 on FOS side.
If you still see the same error, then please open a FortiManager support ticket, so we can check this further.