Hi folks, I'm confused about maximum values supported for Phase2 tunnels by fortigate 300E. (VPN concentrator, mostly dial-up IPsec VPNs)
Datasheet said: Client-to-Gateway IPsec VPN Tunnels:50,000, but even TAC don't explain if is related to phase1 or phase2. In my understanding is about total.
There are any another way to find out this information?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @roni_lucas ,
Your inquiry best fits this guide below which talks about the effect of increasing the number of characters in your VPN name :
- https://community.fortinet.com/t5/Blogs/IPSec-Remote-Access-VPN-Naming-Limitations-on-FortiGate/ba-p...
Other reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-VPN-phase1-interface-name-characters...
Client-to-Gateway is a performance-based number. (you can have a single phase1+phase2 config for a dialup hub = FGT, and up to that many remote clients)
Compare this with Gateway-to-Gateway config, where the number is derived from policy-based tunnels (= the tablesize limit of "config vpn ipsec phase1").
The limit to configured phase2-interface selectors should be 512 per single phase1.
Hello @roni_lucas
You can always look into max value table for a particular model. Please follow the link below:
https://docs.fortinet.com/max-value-table
Regards,
Verender
Try "print tablesize" in the FortiGate CLI.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.