FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
serge_FTNT
Staff
Staff
Article Id 421616
Description This article describes the values of FortiGate system resources.
Scope FortiGate.
Solution

View the 'default Maximum' in GUI-Global resources under global scope, and confirm the value with the console output of the CLI command 'get system resource-limits'.

 

This value '42048' below the column 'default Maximum' is the total sum for Firewall Addresses, which contain the following:

  • IP address (IPv4), IP address6 (IPv6) 
  • IP multicast-address, IP multicast-address6

 

The 'Override Maximum' column in the GUI's Global resources section offers an option to lower the maximum value.

 

For other values:

  • Firewall Policies: include policy+ policy6 + policy46 + policy64 + dos-policy + dos-policy6 + multicast-policy
  • Firewall Address Group: include addrgrp + addrgrp6
  • Session: include session + session6.

 

Example in the following screenshot:

 

IP address (IPv4) (25 used), IP address6 (IPv6) (1 used), while the 'Override Maximum' value is decreased to '15.000'.

 

KB-resource limit.png

 

 

The FortiGate resource maximum values can also be checked from Maximum Values Table