FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
bstefanovski
Staff
Staff
Article Id 413695
Description

This article describes when running a Security Rating check, and encountering the following message:

 

This device is exempt from the requirements for the following reason: Configuration has too many entries to check.

Scope FortiGate.
Solution

When running the Security Rating, the following message appears:

 

image (19).png

 

The error message is an intended limitation to prevent high memory consumption by
configurations with large object counts, and this defeats the purpose of the Security Rating for enterprise users who will have larger configurations.

 

This usually happens on devices with very large configurations, such as many firewall policies, address objects, and groups. When the configuration becomes too big, the Security Rating engine cannot process all entries.

As a result, some checks are skipped, and the device is marked as exempt, preventing a full security assessment.

 

Tip: Regularly cleaning up unused objects and old policies can help improve Security Rating results.

 

For more information, reach out to Fortinet TAC by opening a Support case.

 

Related article: 

Technical Tip: Security Rating entries shown as Unlicensed