- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Phase2 values Fortigate 300E
Hi folks, I'm confused about maximum values supported for Phase2 tunnels by fortigate 300E. (VPN concentrator, mostly dial-up IPsec VPNs)
Datasheet said: Client-to-Gateway IPsec VPN Tunnels:50,000, but even TAC don't explain if is related to phase1 or phase2. In my understanding is about total.
There are any another way to find out this information?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @roni_lucas ,
Your inquiry best fits this guide below which talks about the effect of increasing the number of characters in your VPN name :
- https://community.fortinet.com/t5/Blogs/IPSec-Remote-Access-VPN-Naming-Limitations-on-FortiGate/ba-p...
Other reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-VPN-phase1-interface-name-characters...
Pau
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Client-to-Gateway is a performance-based number. (you can have a single phase1+phase2 config for a dialup hub = FGT, and up to that many remote clients)
Compare this with Gateway-to-Gateway config, where the number is derived from policy-based tunnels (= the tablesize limit of "config vpn ipsec phase1").
The limit to configured phase2-interface selectors should be 512 per single phase1.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @roni_lucas
You can always look into max value table for a particular model. Please follow the link below:
https://docs.fortinet.com/max-value-table
Regards,
Verender
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try "print tablesize" in the FortiGate CLI.
![](/skins/images/EC9FF2F7BE06D4243426EA19DD2C8052/responsive_peak/images/icon_anonymous_message.png)