Hello Experts,
just to wanted to know how many IPsec tunnel can be established on fortigate?
is there any way to calculate how much bandwidth , disk , Memory and CPU utilization will be needed to establish each IPsec tunnel?
I have two Fortigate Virtual machine installed on KVM and fully licensed.
if I want to create multiple IPsec tunnel into my test lab, do i need to install more Fortigate VM to create ipsec tunnel? is there any way i could create multiple IPsec tunnels between two devices?
Hi duahimanshu,
1. I'm not aware of any formula.
When in comes to the max number of the ipsec tunnels you can configure on FGT VM, that's not specified in the sheet. I believe you can configure a pretty big number.
https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/fortigate-vm.pdf
Depending on your VM resources, you might exhaust your cpu/ram/bandwidth way before maxing out the total number of allowed ipsec tunnels.
You'll have to try it out.
For a hardware unit, this it is specified because of the known/limited resources the unit has.
https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/Fortinet_Product_Matrix.pdf
2. You can set up multiple tunnels between the same firewalls, as far as I know.
You'll need to set peerid in order to tell each end to which exact tunnel to connect.
And then you can bundle them into a sdwan interface and use that instead in the policies:
Let me know if this helps.
You can look up limits in the Maximum Values list, which nowadays is interactive:
https://docs.fortinet.com/max-value-table
For example, a VM0 has a max. number of interfaces of 4K, and a max. no. of IPsec tunnels of 2000.
As there are no HW accelerators in a FGT-VM (though, look up "vSPU"), your real limit will be set way lower by the no. of CPU cores, and type of, of your hypervisor. It totally depends on your VM infrastructure. I'd guess you could run a couple of dozens on average HW but don't take my word for it. Test, test, test.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.