Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
roni_lucas
New Contributor II

Phase2 values Fortigate 300E

Hi folks, I'm confused about maximum values supported for Phase2 tunnels by fortigate 300E. (VPN concentrator, mostly dial-up IPsec VPNs)

 

Datasheet said: Client-to-Gateway IPsec VPN Tunnels:50,000, but even TAC don't explain if is related to phase1 or phase2. In my understanding is about total.

There are any another way to find out this information?

4 REPLIES 4
pdelapena
Staff
Staff

Hi @roni_lucas ,

Your inquiry best fits this guide below which talks about the effect of increasing the number of characters in your VPN name :
https://community.fortinet.com/t5/Blogs/IPSec-Remote-Access-VPN-Naming-Limitations-on-FortiGate/ba-p...

Other reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-VPN-phase1-interface-name-characters...



Best regards,
Pau
pminarik
Staff
Staff

Client-to-Gateway is a performance-based number. (you can have a single phase1+phase2 config for a dialup hub = FGT, and up to that many remote clients)

Compare this with Gateway-to-Gateway config, where the number is derived from policy-based tunnels (= the tablesize limit of "config vpn ipsec phase1").

 

The limit to configured phase2-interface selectors should be 512 per single phase1.

[ corrections always welcome ]
KumarV
Staff
Staff

Hello @roni_lucas 

 

You can always look into max value table for a particular model. Please follow the link below:

 

https://docs.fortinet.com/max-value-table

 

Regards,

Verender

Renante_Era
Staff
Staff

Try "print tablesize" in the FortiGate CLI.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors