Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dattatray
New Contributor

Entry limit of Link Monitoring in FortiGate 400F

I have 400F device and on this device we have configured around 1000 site to site VPN tunnels in active passive mode. We need to configure 330 link monitoring entries. I am able to configure 256 entries after that getting an error reached maximum entries. How can we increase the limit of link monitoring entries. 

 

Dattatray
Dattatray
3 REPLIES 3
saleha
Staff
Staff

Hi Dattatray,

Thank you for your inquiry. There are no options to increase beyond maximum value as this is a design limit. I would alternatively recommend considering sdwan configuration instead of link monitor which would be a migration project as the tunnel interfaces have to be not referenced in other config specially firewall policies before they can become sdwan members. On the plus side though sdwan offers the amount of health-checks entries you need according the max value table for 400F models and SDWAN offers more granular control and management of routing.

sdwan reference: https://docs.fortinet.com/document/fortigate/7.4.5/administration-guide/431448/sd-wan-overview

max value table: https://docs.fortinet.com/max-value-table

 

Thank you,

saleha

gonibho1
Visitor

Not always. In one work, they used HEC for SAP. Have 2 tunnel. Only Failover supported in the HEC side. Not support DPD. And if we send traffic acrross secondary tunnel, this make asymetric traffic. Worst deal ever. (Sorry for my bad english)

Toshi_Esumi
SuperUser
SuperUser

Another option is a routing protocol if the other end support any. We use BGP(eBGP) for about 1000 locations. Otherwise, it's time for adding another FGT.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors