FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
arahman
Staff
Staff
Article Id 375122
Description This article describes the troubleshooting steps when trying to push policies from FortiManager to FortiGate the FortiManager policy push fails and gives the error 'error :3 -max entry. object: firewall address. details: global limit. solution: limit is 5000'.
Scope FortiGate, FortiManager.
Solution

When trying to push policies from FortiManager to FortiGate the FortiManager policy push is failed and gives the error 'error :3 -max entry. object: firewall address. details: global limit. solution: limit is 5000'

 

Kb 14.1.PNG

 

This happens when the Maximum table value size of the FortiGate reaches its limit. The table size limit can vary from FortiGate to FortiGate and can be found  Maximum Values Table. And this table size cannot be increased as it is a fixed limit. 

 

On FortiGate, it can be checked from the GUI under System -> Global Resources.

 

Kb 14.2.jpeg

 

Alternatively, it can also be checked with the command below:

 

print tablesize

 

The solution is to delete all of the unused firewall addresses from the FortiGate so the table size frees up. It can be done under Policies & Objects -> Addresses.

 

Kb 14.3.PNG

 

Once all of the unused or unwanted firewall addresses are removed the policy push from the FortiManager to FortiGate will be successful.