Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
harald21
Contributor

No new VPN tunnel - " Maximum number of entries has been reached."

Hi, one of our customers has a FG80C-Cluster running FOS 3.00 MR7p7 (build 750). They have 50 tunnel configured in " Tunnel Mode" and 3 tunnel in " Interface Mode" . When trying to create an new tunnel they get the message " Maximum number of entries has been reached." According to the product description this device supports up to 200 site-to-site ipsec tunnels. Any idea whats going on there? Many thanks in advance. Sincerely Harald
5 REPLIES 5
abelio
SuperUser
SuperUser

Hi,
Any idea whats going on there?
does that unit have VDOM enabled? There' re different max features limits per VDOM once enabled.

regards




/ Abel

regards / Abel
harald21

Hi abelio, VDOM' s are disabled (just the default " root" VDOM exists). Sincerely Harald
rwpatterson
Valued Contributor III

The 200 I see in the maximum values matrix is for certificates. There' s a limit of 50 phase 1 definitions per VDOM on your unit. Check here: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FortiGatev30MaximumValuesMatrix01-30007-0391-20090914pdf&sliceId=&docTypeID=DT_PRODUCTDOCUMENTATION_1_1&dialogID=5949305&stateId=0%200%205947939

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
harald21

Hi, I just checked your link. At page #9 there are the following values for a Fortigate-80: Phase1 per VDOM: 50 or Phase1 per unit: " no set limit" As I don' t use VDOM' s there shouldn' t be any limit (except the used memory of the device). Sincerely Harald
rwpatterson
Valued Contributor III

ORIGINAL: harald21 As I don' t use VDOM' s there shouldn' t be any limit (except the used memory of the device).
You do use VDOMs, you just don' t realize it. You are configuring the root VDOM. Configure the rest in interface mode. You have a limit of 255 interfaces to play with. This is independent of the 50 phase 1 limit.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors