Description
This article explains the output of ‘diagnose vpn ssl statistics’ that is often used to check the maximum number of users that connect to SSL VPN.
Scope
FortiGate.
Solution
In order to check the maximum number of users that a FortiGate can support for SSL VPN, one needs to check the datasheet of that particular unit.
As an example for FortiGate-500E: https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_500E.pdf
Concurrent SSL-VPN Users - 10,000
(Recommended Maximum, Tunnel Mode)
In the following datasheet, it can be seen that the maximum number of concurrent SSL VPN users supported by the unit is 10,000 when used in tunnel mode for FortiGate-500E.
The maximum number also relies upon the memory usage on FortiGate.
The output of the command 'diagnose vpn ssl statistics' can be broken down as follows:
diag vpn ssl statistics
SSLVPN statistics (root):
------------------
Memory unit: 1
System total memory: 1954324480
System free memory: 618819584
SSLVPN memory margin: 195432448
SSLVPN state: normal
The values below indicate the highest number of simultaneous connections since FortiGate was restarted.
It is not a maximum value or limitation.
Max number of users: 7
Max number of tunnels: 7
Max number of connections: 24
These values show the current connections (SSL VPN or users) that were up when the command was executed:
Current number of users: 1
Current number of tunnels: 1
Current number of connections: 1
Related articles:
- Troubleshooting Tip: SSL VPN Troubleshooting
- Technical Tip: FortiGate SSL VPN best practices guide
- Technical Tip: SSL VPN with external DHCP Server
- Technical Tip: How to increase the SSL-VPN tunnel mode bandwidth for small model (multi SSL-VPN clie...
- Technical Tip: Reasons for the 'iprope_in_check() failed' error in SSL VPN
- Troubleshooting Tip: Error 'SSL-VPN slow file transfer issue'
- Technical Tip: FortiGate IPSec VPN Resource List
- Technical Tip: FortiGate Resource Lists