Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

connection limit

My fortigate 100a was recomended for 100 or less users. I have 60 users. I frequently hit my connection limit. does anyone know how to increase or remove the connection limits? Thanks in advance.... Bonz
11 REPLIES 11
abelio
SuperUser
SuperUser

My fortigate 100a was recomended for 100 or less users. I have 60 users.
ftg units doesn' t count users; to dimensionate an unit, it' s necessary evaluate several parameters, network usage, expected traffic, expected filtering requirements, etc. etc
you can' t remove it; you could with tuning your config; use http://kc.forticare.com/default.asp?id=1076&SID=&Lang=1 as reference. maybe you can shutdown features you don' t need. If you' ve already done that, you could need a bigger box.

regards




/ Abel

regards / Abel
Not applicable

abelio
thanks abelio, thats what i figured. didn' t know if someone had some tricks up their sleeve.
Not applicable

In a related issue, does anyone know if it is possible to limit the number of connections per IP or per FW policy match? I sometimes have a few users who suck up so many connections that I hit the limit and it messes things up for everybody. Thanks!
Not applicable

My fgt is 60 with 80 users, I always hit connection limit . If I use FGT-200A to replace fgt-60, connection limit is removed or not?
laf
New Contributor II

My fgt is 60 with 80 users, I always hit connection limit . If I use FGT-200A to replace fgt-60, connection limit is removed or not?
A 200A will no longer give you: connection limit, I think. Still if you ll change your number of user or your internet connection with a bigger one...I recommend you a FG 310B. Also be aware that FG200A already became obsolete since Octomber this year ;).
In a related issue, does anyone know if it is possible to limit the number of connections per IP or per FW policy match? I sometimes have a few users who suck up so many connections that I hit the limit and it messes things up for everybody. Thanks!
I would make a special firewall policy for the guys that are exceeding my bandwidth and restrict their services and also use Traffic shaping and simply restrict their maximum bandwidh ;).

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
Not applicable

How about FGT-224B ? Compared with FGT-200A, FGT-224B is suitable for my environment?
laf
New Contributor II

How about FGT-224B ? Compared with FGT-200A, FGT-224B is suitable for my environment?
:-? have you read www.fortinet.com/products ? 224B and 200A have the same performances; 80 users should be ok for the 200A as I could see from my previouses installations, still what' s your Internet bandwidth? do you have IPS and DOS enabled?

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
FortiRack_Eric
New Contributor III

I think you should analyse why it hits connection limit. On a FG60 can very well be wrong firmware version. Connection limit on the console will also refer to conserve mode. The real connection limits are very high. I believe it' s something of 50.000 connections for a FG60. That should be sufficient. So my strong believe you don' t need more than 50.000 connections for 80 users. Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

AV, IPS ,antispam and Web filter are all enabled. In the furture, VPN connections (site to site IPSEC, SSL VPN) are under consideration. 200A or 224B is suitable for these service and local 80 users?
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors