This article describes how to resolve an issue where the 'Entries' field is missing from the IP Address External Threat Feed, even though the connection status shows as successful.
FortiGate.
For an IP Address External threat feed (IP Address External Feed, Type, Update method, URL, Connection status, Last Content Update and Entries), fields will be displayed once the file loads successfully.
The image below shows that the 'Entries' tab is missing in the IP Address External Threat Feed despite the connection status indicating success.
In this scenario, four external feeds are configured, with the first three containing a total of 300,000 IP addresses. Adding more than 300,000 entries may cause the 'Entries' field not to display, so it is important to ensure the IP Address External Feed configurations remain consistent.
The maximum number of entries allowed for each type per model range up to version 7.6.2 was 300,000. See the Threat feeds - FortiGate 7.6.2 administration guide.
From v7.6.3, the IP address capacity on mid-range FortiGate models has been raised from 300,000 to 1,000,000.
On high-end FortiGate models, the number of IP addresses has been increased from 300,000 to 5,000,000.
Verify the connection between FortiGate and the Threat Feed server, since an unstable connection could cause a similar issue. If the connection is unstable, the entries would not be visible intermittently, even after having less number of entries in Threat Feed: Troubleshooting Tip: How to Troubleshoot external threat feed server not connecting
Related documents:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.