Fortinet white logo
Fortinet white logo

Maximum values for FortiPAM hardware appliances and VM

Maximum values for FortiPAM hardware appliances and VM

The following table lists the maximum number of configuration objects per FortiPAM appliance that can be added to the configuration database for different FortiPAM hardware or VM models.

Features

Table-instance limit 1

(VDOM limit) 2

[Global limit]3

FortiPAM 1000G

FortiPAM 3000G

FortiPAM-VM

Secret

Folder

2000

(2000)

[2000]

6000

(6000)

[6000]

6000

(6000)

[6000]

Database

5000

(5000)

[5000]

10000

(10000)

[10000]

10000

(10000)

[10000]

Request

5000

(5000)

[5000]

10000

(10000)

[10000]

10000

(10000)

[10000]

Secret launcher

Initial commands

64

(0)

[0]

64

(0)

[0]

64

(0)

[0]

Clean commands

64

(0)

[0]

64

(0)

[0]

64

(0)

[0]

System

Zone

0

(200)

[0]

0

(500)

[0]

0

(500)

[0]

Zone interface

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

Interface

0

(0)

[8192]

0

(0)

[8192]

0

(0)

[8192]

Interface secondary IP address

32

(0)

[0]

32

(0)

[0]

32

(0)

[0]

Interface IPv6 prefix list

32

(0)

[0]

32

(0)

[0]

32

(0)

[0]

Interface DHCP snooping server list

255

(0)

[2048]

255

(0)

[2048]

255

(0)

[2048]

Account profile

0

(0)

[64]

0

(0)

[64]

0

(0)

[64]

Admin

0

(0)

[1000]

0

(0)

[3000]

0

(0)

[3000]

SNMP community

0

(0)

[3]

0

(0)

[3]

0

(0)

[3]

SNMP community hosts

16

(0)

[0]

16

(0)

[0]

16

(0)

[0]

SNMP community hosts6

16

(0)

[0]

16

(0)

[0]

16

(0)

[0]

SNMP user

0

(0)

[32]

0

(0)

[32]

0

(0)

[32]

Session TTL port

0

(512)

[0]

0

(512)

[0]

0

(512)

[0]

DHCP server

0

(1024)

[0]

0

(4192)

[0]

0

(4192)

[0]

DHCP server options

30

(0)

[0]

30

(0)

[0]

30

(0)

[0]

DHCP server reserved address

0

(5000)

[0]

0

(5000)

[0]

0

(5000)

[0]

DHCP server IP range

3

(0)

[0]

3

(0)

[0]

3

(0)

[0]

DHCP server exclude range

16

(0)

[0]

16

(0)

[0]

16

(0)

[0]

MAC address table

0

(2000)

[0]

0

(2000)

[0]

0

(2000)

[0]

ARP table

0

(16834)

[16834]

0

(16834)

[16834]

0

(16834)

[16834]

Proxy ARP

0

(256)

[0]

0

(256)

[0]

0

(256)

[0]

TOS based priority

0

(16)

[0]

0

(16)

[0]

0

(16)

[0]

DSCP based priority

0

(64)

[0]

0

(64)

[0]

0

(64)

[0]

Replacement message group

0

(200)

[0]

0

(200)

[0]

0

(200)

[0]

Central management server list

100

(0)

[0]

100

(0)

[0]

100

(0)

[0]

Replacement message images

0

(0)

[21]

0

(0)

[21]

0

(0)

[21]

SAML service-providers assertion-attributes

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

DNS server hostname

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

DDNS server IP

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

VDOM DNS server-hostname

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

DNS database

0

(4096)

[0]

0

(4096)

[0]

0

(4096)

[0]

DNS IPS URL filter

0

(0)

[20]

0

(0)

[20]

0

(0)

[20]

DNS6 IPS URL filter

0

(0)

[20]

0

(0)

[20]

0

(0)

[20]

GRE tunnel

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

VXLAN

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

User

RADIUS server

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

pop3

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

RADIUS accounting server

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

TACACS+ server

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

LDAP server

0

(64)

[0]

0

(64)

[0]

0

(64)

[0]

SAML server

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

FortiTokens

0

(0)

[1000]

0

(0)

[5000]

0

(0)

[5000]

Local

0

(5000)

[0]

0

(0)

[0]

0

(0)

[0]

Peer

0

(5000)

[0]

0

(0)

[0]

0

(0)

[0]

Peer user group

0

(5000)

[0]

0

(5000)

[0]

0

(5000)

[0]

Peer user group members

50000

(0)

[0]

50000

(0)

[0]

50000

(0)

[0]

Address groups

0

(1024)

[1024]

0

(8192)

[8192]

0

(8192)

[8192]

User FSSO polling address groups

0

(1024)

[0]

0

(8192)

[0]

0

(8192)

[0]

User group

0

(2000)

[0]

0

(5000)

[0]

0

(5000)

[0]

User group members

3000

(0)

[0]

3000

(0)

[0]

3000

(0)

[0]

User group guests

1024

(0)

[0]

1024

(0)

[0]

1024

(0)

[0]

FSSO

0

(5)

[0]

0

(5)

[0]

0

(5)

[0]

FSSO polling

0

(100)

[100]

0

(100)

[100]

0

(100)

[100]

Web filter FortiGuard local

0

(52)

[0]

0

(52)

[0]

0

(52)

[0]

Firewall

Address

0

(40000)

[40000]

0

(100000)

[100000]

0

(100000)

[100000]

IPv6 Address

0

(40000)

[40000]

0

(100000)

[100000]

0

(100000)

[100000]

Custom wildcard FQDN

0

(512)

[512]

0

(512)

[512]

0

(512)

[512]

Wildcard FQDN group

0

(512)

[512]

0

(512)

[512]

0

(512)

[512]

Proxy address

0

(24576)

[24576]

0

(24576)

[24576]

0

(24576)

[24576]

Service custom

0

(1024)

[0]

0

(4096)

[0]

0

(4096)

[0]

Service group

0

(4000)

[0]

0

(10000)

[0]

0

(10000)

[0]

Service group member

300

(0)

[0]

300

(0)

[0]

300

(0)

[0]

Onetime schedule

0

(5000)

[0]

0

(5000)

[0]

0

(5000)

[0]

Recurring schedule

0

(1024)

[0]

0

(1024)

[0]

0

(1024)

[0]

IP pool

0

(512)

[0]

0

(512)

[0]

0

(512)

[0]

Profile group

0

(1000)

[1000]

0

(20000)

[20000]

0

(20000)

[20000]

Profile protocol options

0

(500)

[500]

0

(500)

[500]

0

(500)

[500]

SSH profile

0

(500)

[500]

0

(500)

[500]

0

(500)

[500]

SSH profile SSL exempt

255

(0)

[0]

255

(0)

[0]

255

(0)

[0]

Firewall VIP

0

(32768)

[32768]

0

(32768)

[32768]

0

(32768)

[32768]

VIP monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP real servers

64

(0)

[0]

256

(0)

[0]

256

(0)

[0]

VIP real servers monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP group

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

VIP group member

500

(0)

[0]

500

(0)

[0]

500

(0)

[0]

IP MAC binding table

0

(2048)

[0]

0

(2048)

[0]

0

(2048)

[0]

Address group

0

(20000)

[20000]

0

(20000)

[20000]

0

(20000)

[20000]

Address group IPv6

0

(20000)

[20000]

0

(20000)

[20000]

0

(20000)

[20000]

Address group member

1500

(0)

[0]

0

(0)

[0]

0

(0)

[0]

Proxy address group

0

(4096)

[4096]

0

(4096)

[4096]

0

(4096)

[4096]

Proxy address group member

24000

(0)

[0]

24000

(0)

[0]

24000

(0)

[0]

SSH host key

2000

(0)

[0]

2000

(0)

[0]

2000

(0)

[0]

SSH local key

0

(100)

[0]

0

(100)

[0]

0

(100)

[0]

SSH local CA

0

(100)

[0]

0

(100)

[0]

0

(100)

[0]

Policy

0

(100000)

[100000]

0

(200000)

[200000]

0

(200000)

[200000]

Custom log fields

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

Poolname

64

(0)

[0]

64

(0)

[0]

64

(0)

[0]

VIP6

0

(32768)

[32768]

0

(32768)

[32768]

0

(32768)

[32768]

VIP6 monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP6 real servers

32

(0)

[0]

32

(0)

[0]

32

(0)

[0]

VIP6 real servers monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP6 group

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

VIP6 group member

500

(0)

[0]

500

(0)

[0]

500

(0)

[0]

Central SNAT map

0

(30000)

[30000]

0

(30000)

[30000]

0

(30000)

[30000]

Internet service entry port-range

0

(0)

[64]

0

(0)

[64]

0

(0)

[64]

Service category

0

(5000)

[5000]

0

(10000)

[10000

0

(10000)

[10000

WAN OPT profile

0

(128)

[0]

0

(256)

[0]

0

(256)

[0]

WAN OPT peer

0

(1024)

[0]

0

(2048)

[0]

0

(2048)

[0]

WAN OPT authentication group

0

(128)

[0]

0

(256)

[0]

0

(256)

[0]

WAN OPT SSL server

0

(128)

[0]

0

(256)

[0]

0

(256)

[0]

LDP monitor

0

(256)

[0]

0

(512)

[0]

0

(512)

[0]

Traffic shaper

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

VPN SSL web portal

0

(2600)

[2600]

0

(2600)

[2600]

0

(2600)

[2600]

VPN SSL web portal: bookmark-group: bookmarks

256

(0)

[0]

256

(0)

[0]

256

(0)

[0]

VPN SSL web user group: bookmark

0

(2000)

[2600]

0

(2000)

[2600]

0

(2000)

[2600]

VPN SSL web user group bookmark: bookmarks

128

(0)

[0]

128

(0)

[0]

128

(0)

[0]

VPN SSL web user bookmark: bookmarks

128

(0)

[0]

128

(0)

[0]

128

(0)

[0]

IPS: custom

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

Router

Static

0

(10000)

[0]

0

(10000)

[0]

0

(10000)

[0]

Policy

0

(2048)

[2048]

0

(2048)

[2048]

0

(2048)

[2048]

Static6

0

(10000)

[0]

0

(10000)

[0]

0

(10000)

[0]

VPN

Local certificate

0

(500)

[0]

0

(1000)

[0]

0

(1000)

[0]

CA certificate

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

CRL certificate

0

(200)

[0]

0

(200)

[0]

0

(200)

[0]

IPSec phase1 interface

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

IPSec phase2 interface

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

Web filter FortiGuard: local rating

0

(12000)

[0]

0

(12000)

[0]

0

(12000)

[0]

Application

List

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

Custom

0

(1000)

[0]

0

(9000)

[0]

0

(9000)

[0]

CASI profile

0

(256)

[256]

0

(1000)

[1000

0

(1000)

[1000

IPS

Sensor

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

Sensor override exempt IP address

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Web filter

Profile

0

(1000)

[1000]

0

(20000)

[20000]

0

(20000)

[20000]

Web keyword-match

0

(64)

[0]

0

(64)

[0]

0

(64)

[0]

Content

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Content entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Exmword

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Exmword entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

URL filter

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

URL filter entries

0

(32000)

[32000]

0

(250000)

[250000]

0

(250000)

[250000]

Override

0

(200)

[0]

0

(500)

[0]

0

(500)

[0]

DNS filter

Profile

0

(32)

[32]

0

(500)

[500]

0

(500)

[500]

Domain filter

0

(32)

[32]

0

(256)

[256]

0

(256)

[256]

Profile: domain-filter: external-blocklist

10

(0)

[0]

10

(0)

[0]

10

(0)

[0]

Domain filter entries

0

(32000)

[32000]

0

(250000)

[250000]

0

(250000)

[250000]

Email filter

Profile

0

(32)

[0]

0

(500)

[0]

0

(500)

[0]

Bword

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Block allowlist

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

DNSBL

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

IP trust

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Mheader

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Bword entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Block allow list entries

0

(100000)

[0]

0

(500000)

[0]

0

(500000)

[0]

DNSBL entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

IP trust entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Mheader entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Antivirus

Profile

0

(32)

[0]

0

(500)

[0]

0

(500)

[0]

Content type

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

DLP

File pattern entries

32000

(0)

[0]

250000

(0)

[0]

250000

(0)

[0]

File pattern

0

(5000)

[5000]

0

(12500)

[12500]

0

(12500)

[12500]

Sensor

0

(1000)

[1000]

0

(1500)

[1500]

0

(1500)

[1500]

Sensor filter

3000

(0)

[0]

4000

(0)

[0]

4000

(0)

[0]

Sensitivity

0

(128)

[0]

0

(128)

[0]

0

(128)

[0]

File filter

Profile

0

(1000)

[1000]

0

(1500)

[1500]

0

(1500)

[1500]

Profile rules

3000

(0)

[0

4000

(0)

[0]

4000

(0)

[0]

Report layout

Report layout

0

(32)

[0]

0

(32)

[0]

0

(32)

[0]

Body item

256

(0)

[0]

256

(0)

[0]

256

(0)

[0]

Page header item

2

(0)

[0]

2

(0)

[0]

2

(0)

[0]

Page footer item

2

(0)

[0]

2

(0)

[0]

2

(0)

[0]

Log threat

Weight geolocation

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

Weight web

0

(96)

[0]

0

(96)

[0]

0

(96)

[0]

Weight application

0

(32)

[0]

0

(32)

[0]

0

(32)

[0]

Log setting: custom-log-fields

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

Log tap-device

0

(0)

[3]

0

(0)

[3]

0

(0)

[3]

System automation-trigger: fields

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

SSH-filter.profile: shell-commands

256

(0)

[0]

256

(0)

[0]

256

(0)

[0]

Endpoint-control fctems

0

(0)

[5]

0

(0)

[5]

0

(0)

[5]

System object-tagging

0

(4096)

[4096]

0

(4096)

[4096]

0

(4096)

[4096]

System HA: HA-mgmt-interfaces

0

(0)

[1]

0

(0)

[1]

0

(0)

[1]

System HA:unicast-peers

0

(0)

[7]

0

(0)

[7]

0

(0)

[7]

System SDN-connector

0

(0)

[16]

0

(0)

[16]

0

(0)

[16]

Log FortiAnalyzer setting: serial

8

(0)

[0

8

(0)

[0

8

(0)

[0

Log ForitAnalyzer2 setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log ForitAnalyzer3 setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log FortiAnalyzer override setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log FortiAnalyzer2 override setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log FortiAnalyzer3 override setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

System SSO Admin

0

(0)

[300]

0

(0)

[550]

0

(0)

[550]

Firewall internet-service-name

0

(0)

[8192]

0

(0)

[8192]

0

(0)

[8192]

System SSO-FortiCloud-admin

0

(0)

[300]

0

(0)

[550]

0

(0)

[550]

System NETHSM: servers

0

(0)

[2]

0

(0)

[2]

0

(0)

[2]

System NETHSM: slots

0

(0)

[10]

0

(0)

[10]

0

(0)

[10]

System NETHSM: HA group

0

(0)

[2]

0

(0)

[2]

0

(0)

[2]

System interface MAC

0

(0)

[600]

0

(0)

[600]

0

(0)

[600]

1The maximum number of entries in each table instance.

2The maximum number of entries over all tables of the same type within each VDOM.

3The maximum number of entries over all tables of the same type within the system.

Note: 0 indicates no limit.

Maximum values for FortiPAM hardware appliances and VM

Maximum values for FortiPAM hardware appliances and VM

The following table lists the maximum number of configuration objects per FortiPAM appliance that can be added to the configuration database for different FortiPAM hardware or VM models.

Features

Table-instance limit 1

(VDOM limit) 2

[Global limit]3

FortiPAM 1000G

FortiPAM 3000G

FortiPAM-VM

Secret

Folder

2000

(2000)

[2000]

6000

(6000)

[6000]

6000

(6000)

[6000]

Database

5000

(5000)

[5000]

10000

(10000)

[10000]

10000

(10000)

[10000]

Request

5000

(5000)

[5000]

10000

(10000)

[10000]

10000

(10000)

[10000]

Secret launcher

Initial commands

64

(0)

[0]

64

(0)

[0]

64

(0)

[0]

Clean commands

64

(0)

[0]

64

(0)

[0]

64

(0)

[0]

System

Zone

0

(200)

[0]

0

(500)

[0]

0

(500)

[0]

Zone interface

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

Interface

0

(0)

[8192]

0

(0)

[8192]

0

(0)

[8192]

Interface secondary IP address

32

(0)

[0]

32

(0)

[0]

32

(0)

[0]

Interface IPv6 prefix list

32

(0)

[0]

32

(0)

[0]

32

(0)

[0]

Interface DHCP snooping server list

255

(0)

[2048]

255

(0)

[2048]

255

(0)

[2048]

Account profile

0

(0)

[64]

0

(0)

[64]

0

(0)

[64]

Admin

0

(0)

[1000]

0

(0)

[3000]

0

(0)

[3000]

SNMP community

0

(0)

[3]

0

(0)

[3]

0

(0)

[3]

SNMP community hosts

16

(0)

[0]

16

(0)

[0]

16

(0)

[0]

SNMP community hosts6

16

(0)

[0]

16

(0)

[0]

16

(0)

[0]

SNMP user

0

(0)

[32]

0

(0)

[32]

0

(0)

[32]

Session TTL port

0

(512)

[0]

0

(512)

[0]

0

(512)

[0]

DHCP server

0

(1024)

[0]

0

(4192)

[0]

0

(4192)

[0]

DHCP server options

30

(0)

[0]

30

(0)

[0]

30

(0)

[0]

DHCP server reserved address

0

(5000)

[0]

0

(5000)

[0]

0

(5000)

[0]

DHCP server IP range

3

(0)

[0]

3

(0)

[0]

3

(0)

[0]

DHCP server exclude range

16

(0)

[0]

16

(0)

[0]

16

(0)

[0]

MAC address table

0

(2000)

[0]

0

(2000)

[0]

0

(2000)

[0]

ARP table

0

(16834)

[16834]

0

(16834)

[16834]

0

(16834)

[16834]

Proxy ARP

0

(256)

[0]

0

(256)

[0]

0

(256)

[0]

TOS based priority

0

(16)

[0]

0

(16)

[0]

0

(16)

[0]

DSCP based priority

0

(64)

[0]

0

(64)

[0]

0

(64)

[0]

Replacement message group

0

(200)

[0]

0

(200)

[0]

0

(200)

[0]

Central management server list

100

(0)

[0]

100

(0)

[0]

100

(0)

[0]

Replacement message images

0

(0)

[21]

0

(0)

[21]

0

(0)

[21]

SAML service-providers assertion-attributes

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

DNS server hostname

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

DDNS server IP

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

VDOM DNS server-hostname

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

DNS database

0

(4096)

[0]

0

(4096)

[0]

0

(4096)

[0]

DNS IPS URL filter

0

(0)

[20]

0

(0)

[20]

0

(0)

[20]

DNS6 IPS URL filter

0

(0)

[20]

0

(0)

[20]

0

(0)

[20]

GRE tunnel

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

VXLAN

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

User

RADIUS server

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

pop3

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

RADIUS accounting server

4

(0)

[0]

4

(0)

[0]

4

(0)

[0]

TACACS+ server

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

LDAP server

0

(64)

[0]

0

(64)

[0]

0

(64)

[0]

SAML server

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

FortiTokens

0

(0)

[1000]

0

(0)

[5000]

0

(0)

[5000]

Local

0

(5000)

[0]

0

(0)

[0]

0

(0)

[0]

Peer

0

(5000)

[0]

0

(0)

[0]

0

(0)

[0]

Peer user group

0

(5000)

[0]

0

(5000)

[0]

0

(5000)

[0]

Peer user group members

50000

(0)

[0]

50000

(0)

[0]

50000

(0)

[0]

Address groups

0

(1024)

[1024]

0

(8192)

[8192]

0

(8192)

[8192]

User FSSO polling address groups

0

(1024)

[0]

0

(8192)

[0]

0

(8192)

[0]

User group

0

(2000)

[0]

0

(5000)

[0]

0

(5000)

[0]

User group members

3000

(0)

[0]

3000

(0)

[0]

3000

(0)

[0]

User group guests

1024

(0)

[0]

1024

(0)

[0]

1024

(0)

[0]

FSSO

0

(5)

[0]

0

(5)

[0]

0

(5)

[0]

FSSO polling

0

(100)

[100]

0

(100)

[100]

0

(100)

[100]

Web filter FortiGuard local

0

(52)

[0]

0

(52)

[0]

0

(52)

[0]

Firewall

Address

0

(40000)

[40000]

0

(100000)

[100000]

0

(100000)

[100000]

IPv6 Address

0

(40000)

[40000]

0

(100000)

[100000]

0

(100000)

[100000]

Custom wildcard FQDN

0

(512)

[512]

0

(512)

[512]

0

(512)

[512]

Wildcard FQDN group

0

(512)

[512]

0

(512)

[512]

0

(512)

[512]

Proxy address

0

(24576)

[24576]

0

(24576)

[24576]

0

(24576)

[24576]

Service custom

0

(1024)

[0]

0

(4096)

[0]

0

(4096)

[0]

Service group

0

(4000)

[0]

0

(10000)

[0]

0

(10000)

[0]

Service group member

300

(0)

[0]

300

(0)

[0]

300

(0)

[0]

Onetime schedule

0

(5000)

[0]

0

(5000)

[0]

0

(5000)

[0]

Recurring schedule

0

(1024)

[0]

0

(1024)

[0]

0

(1024)

[0]

IP pool

0

(512)

[0]

0

(512)

[0]

0

(512)

[0]

Profile group

0

(1000)

[1000]

0

(20000)

[20000]

0

(20000)

[20000]

Profile protocol options

0

(500)

[500]

0

(500)

[500]

0

(500)

[500]

SSH profile

0

(500)

[500]

0

(500)

[500]

0

(500)

[500]

SSH profile SSL exempt

255

(0)

[0]

255

(0)

[0]

255

(0)

[0]

Firewall VIP

0

(32768)

[32768]

0

(32768)

[32768]

0

(32768)

[32768]

VIP monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP real servers

64

(0)

[0]

256

(0)

[0]

256

(0)

[0]

VIP real servers monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP group

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

VIP group member

500

(0)

[0]

500

(0)

[0]

500

(0)

[0]

IP MAC binding table

0

(2048)

[0]

0

(2048)

[0]

0

(2048)

[0]

Address group

0

(20000)

[20000]

0

(20000)

[20000]

0

(20000)

[20000]

Address group IPv6

0

(20000)

[20000]

0

(20000)

[20000]

0

(20000)

[20000]

Address group member

1500

(0)

[0]

0

(0)

[0]

0

(0)

[0]

Proxy address group

0

(4096)

[4096]

0

(4096)

[4096]

0

(4096)

[4096]

Proxy address group member

24000

(0)

[0]

24000

(0)

[0]

24000

(0)

[0]

SSH host key

2000

(0)

[0]

2000

(0)

[0]

2000

(0)

[0]

SSH local key

0

(100)

[0]

0

(100)

[0]

0

(100)

[0]

SSH local CA

0

(100)

[0]

0

(100)

[0]

0

(100)

[0]

Policy

0

(100000)

[100000]

0

(200000)

[200000]

0

(200000)

[200000]

Custom log fields

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

Poolname

64

(0)

[0]

64

(0)

[0]

64

(0)

[0]

VIP6

0

(32768)

[32768]

0

(32768)

[32768]

0

(32768)

[32768]

VIP6 monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP6 real servers

32

(0)

[0]

32

(0)

[0]

32

(0)

[0]

VIP6 real servers monitor

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

VIP6 group

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

VIP6 group member

500

(0)

[0]

500

(0)

[0]

500

(0)

[0]

Central SNAT map

0

(30000)

[30000]

0

(30000)

[30000]

0

(30000)

[30000]

Internet service entry port-range

0

(0)

[64]

0

(0)

[64]

0

(0)

[64]

Service category

0

(5000)

[5000]

0

(10000)

[10000

0

(10000)

[10000

WAN OPT profile

0

(128)

[0]

0

(256)

[0]

0

(256)

[0]

WAN OPT peer

0

(1024)

[0]

0

(2048)

[0]

0

(2048)

[0]

WAN OPT authentication group

0

(128)

[0]

0

(256)

[0]

0

(256)

[0]

WAN OPT SSL server

0

(128)

[0]

0

(256)

[0]

0

(256)

[0]

LDP monitor

0

(256)

[0]

0

(512)

[0]

0

(512)

[0]

Traffic shaper

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

VPN SSL web portal

0

(2600)

[2600]

0

(2600)

[2600]

0

(2600)

[2600]

VPN SSL web portal: bookmark-group: bookmarks

256

(0)

[0]

256

(0)

[0]

256

(0)

[0]

VPN SSL web user group: bookmark

0

(2000)

[2600]

0

(2000)

[2600]

0

(2000)

[2600]

VPN SSL web user group bookmark: bookmarks

128

(0)

[0]

128

(0)

[0]

128

(0)

[0]

VPN SSL web user bookmark: bookmarks

128

(0)

[0]

128

(0)

[0]

128

(0)

[0]

IPS: custom

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

Router

Static

0

(10000)

[0]

0

(10000)

[0]

0

(10000)

[0]

Policy

0

(2048)

[2048]

0

(2048)

[2048]

0

(2048)

[2048]

Static6

0

(10000)

[0]

0

(10000)

[0]

0

(10000)

[0]

VPN

Local certificate

0

(500)

[0]

0

(1000)

[0]

0

(1000)

[0]

CA certificate

0

(500)

[0]

0

(500)

[0]

0

(500)

[0]

CRL certificate

0

(200)

[0]

0

(200)

[0]

0

(200)

[0]

IPSec phase1 interface

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

IPSec phase2 interface

0

(0)

[0]

0

(0)

[0]

0

(0)

[0]

Web filter FortiGuard: local rating

0

(12000)

[0]

0

(12000)

[0]

0

(12000)

[0]

Application

List

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

Custom

0

(1000)

[0]

0

(9000)

[0]

0

(9000)

[0]

CASI profile

0

(256)

[256]

0

(1000)

[1000

0

(1000)

[1000

IPS

Sensor

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

Sensor override exempt IP address

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Web filter

Profile

0

(1000)

[1000]

0

(20000)

[20000]

0

(20000)

[20000]

Web keyword-match

0

(64)

[0]

0

(64)

[0]

0

(64)

[0]

Content

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Content entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Exmword

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Exmword entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

URL filter

0

(256)

[256]

0

(1000)

[1000]

0

(1000)

[1000]

URL filter entries

0

(32000)

[32000]

0

(250000)

[250000]

0

(250000)

[250000]

Override

0

(200)

[0]

0

(500)

[0]

0

(500)

[0]

DNS filter

Profile

0

(32)

[32]

0

(500)

[500]

0

(500)

[500]

Domain filter

0

(32)

[32]

0

(256)

[256]

0

(256)

[256]

Profile: domain-filter: external-blocklist

10

(0)

[0]

10

(0)

[0]

10

(0)

[0]

Domain filter entries

0

(32000)

[32000]

0

(250000)

[250000]

0

(250000)

[250000]

Email filter

Profile

0

(32)

[0]

0

(500)

[0]

0

(500)

[0]

Bword

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Block allowlist

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

DNSBL

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

IP trust

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Mheader

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

Bword entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Block allow list entries

0

(100000)

[0]

0

(500000)

[0]

0

(500000)

[0]

DNSBL entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

IP trust entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Mheader entries

0

(32000)

[0]

0

(250000)

[0]

0

(250000)

[0]

Antivirus

Profile

0

(32)

[0]

0

(500)

[0]

0

(500)

[0]

Content type

0

(1000)

[0]

0

(2000)

[0]

0

(2000)

[0]

DLP

File pattern entries

32000

(0)

[0]

250000

(0)

[0]

250000

(0)

[0]

File pattern

0

(5000)

[5000]

0

(12500)

[12500]

0

(12500)

[12500]

Sensor

0

(1000)

[1000]

0

(1500)

[1500]

0

(1500)

[1500]

Sensor filter

3000

(0)

[0]

4000

(0)

[0]

4000

(0)

[0]

Sensitivity

0

(128)

[0]

0

(128)

[0]

0

(128)

[0]

File filter

Profile

0

(1000)

[1000]

0

(1500)

[1500]

0

(1500)

[1500]

Profile rules

3000

(0)

[0

4000

(0)

[0]

4000

(0)

[0]

Report layout

Report layout

0

(32)

[0]

0

(32)

[0]

0

(32)

[0]

Body item

256

(0)

[0]

256

(0)

[0]

256

(0)

[0]

Page header item

2

(0)

[0]

2

(0)

[0]

2

(0)

[0]

Page footer item

2

(0)

[0]

2

(0)

[0]

2

(0)

[0]

Log threat

Weight geolocation

0

(10)

[0]

0

(10)

[0]

0

(10)

[0]

Weight web

0

(96)

[0]

0

(96)

[0]

0

(96)

[0]

Weight application

0

(32)

[0]

0

(32)

[0]

0

(32)

[0]

Log setting: custom-log-fields

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

Log tap-device

0

(0)

[3]

0

(0)

[3]

0

(0)

[3]

System automation-trigger: fields

5

(0)

[0]

5

(0)

[0]

5

(0)

[0]

SSH-filter.profile: shell-commands

256

(0)

[0]

256

(0)

[0]

256

(0)

[0]

Endpoint-control fctems

0

(0)

[5]

0

(0)

[5]

0

(0)

[5]

System object-tagging

0

(4096)

[4096]

0

(4096)

[4096]

0

(4096)

[4096]

System HA: HA-mgmt-interfaces

0

(0)

[1]

0

(0)

[1]

0

(0)

[1]

System HA:unicast-peers

0

(0)

[7]

0

(0)

[7]

0

(0)

[7]

System SDN-connector

0

(0)

[16]

0

(0)

[16]

0

(0)

[16]

Log FortiAnalyzer setting: serial

8

(0)

[0

8

(0)

[0

8

(0)

[0

Log ForitAnalyzer2 setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log ForitAnalyzer3 setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log FortiAnalyzer override setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log FortiAnalyzer2 override setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

Log FortiAnalyzer3 override setting: serial

8

(0)

[0]

8

(0)

[0]

8

(0)

[0]

System SSO Admin

0

(0)

[300]

0

(0)

[550]

0

(0)

[550]

Firewall internet-service-name

0

(0)

[8192]

0

(0)

[8192]

0

(0)

[8192]

System SSO-FortiCloud-admin

0

(0)

[300]

0

(0)

[550]

0

(0)

[550]

System NETHSM: servers

0

(0)

[2]

0

(0)

[2]

0

(0)

[2]

System NETHSM: slots

0

(0)

[10]

0

(0)

[10]

0

(0)

[10]

System NETHSM: HA group

0

(0)

[2]

0

(0)

[2]

0

(0)

[2]

System interface MAC

0

(0)

[600]

0

(0)

[600]

0

(0)

[600]

1The maximum number of entries in each table instance.

2The maximum number of entries over all tables of the same type within each VDOM.

3The maximum number of entries over all tables of the same type within the system.

Note: 0 indicates no limit.