Skip to main content
harald21
New Member
April 30, 2010
Question

No new VPN tunnel - " Maximum number of entries has been reached."

  • April 30, 2010
  • 1 reply
  • 4086 views
Hi, one of our customers has a FG80C-Cluster running FOS 3.00 MR7p7 (build 750). They have 50 tunnel configured in " Tunnel Mode" and 3 tunnel in " Interface Mode" . When trying to create an new tunnel they get the message " Maximum number of entries has been reached." According to the product description this device supports up to 200 site-to-site ipsec tunnels. Any idea whats going on there? Many thanks in advance. Sincerely Harald

    1 reply

    abelio
    SuperUser
    SuperUser
    April 30, 2010
    Hi,
    Any idea whats going on there?
    does that unit have VDOM enabled? There' re different max features limits per VDOM once enabled.
    harald21
    harald21Author
    New Member
    May 3, 2010
    Hi abelio, VDOM' s are disabled (just the default " root" VDOM exists). Sincerely Harald
    rwpatterson
    New Member
    May 3, 2010
    The 200 I see in the maximum values matrix is for certificates. There' s a limit of 50 phase 1 definitions per VDOM on your unit. Check here: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FortiGatev30MaximumValuesMatrix01-30007-0391-20090914pdf&sliceId=&docTypeID=DT_PRODUCTDOCUMENTATION_1_1&dialogID=5949305&stateId=0%200%205947939