Maximum values for hardware appliances
This section lists the maximum number of configuration objects per FortiAuthenticator appliance that can be added to the configuration database for different FortiAuthenticator hardware models.
The maximum values in this document are the maximum configurable values and are not a commitment of performance. |
The following table describes the maximum values set for the various hardware models.
Feature | Model | |||||
---|---|---|---|---|---|---|
200E | 400E | 1000D | 2000E | 3000E | ||
System | ||||||
Network | Static Routes | 50 | 50 | 50 | 50 | 50 |
Messages | SMTP Servers | 20 | 20 | 20 | 20 | 20 |
SMS Gateways | 20 | 20 | 20 | 20 | 20 | |
SNMP Hosts | 20 | 20 | 20 | 20 | 20 | |
Administration | Syslog Servers | 20 | 20 | 20 | 20 | 20 |
User Uploaded Images | 39 | 114 | 514 | 1014 | 2014 | |
Language Files | 50 | 50 | 50 | 50 | 50 | |
Realms | 20 | 80 | 400 | 800 | 1600 | |
Authentication | ||||||
General | Auth Clients (NAS) | 166 | 666 | 3333 | 6666 | 13333 |
Users
(Local + Remote)1 |
500 | 2000 | 10000 | 20000 | 40000 | |
User Radius Attributes | 1500 | 6000 | 30000 | 60000 | 120000 | |
User Groups | 50 | 200 | 1000 | 2000 | 4000 | |
Group Radius Attributes | 150 | 150 | 600 | 6000 | 12000 | |
FortiTokens | 1000 | 4000 | 20000 | 40000 | 80000 | |
FortiToken Mobile Licenses2 | 200 | 200 | 200 | 200 | 200 | |
LDAP Entries | 1000 | 4000 | 20000 | 40000 | 80000 | |
Device (MAC-based Auth.) | 2500 | 10000 | 50000 | 100000 | 200000 | |
RADIUS Client Profiles | 500 | 2000 | 10000 | 20000 | 40000 | |
Remote LDAP Servers | 20 | 80 | 400 | 800 | 1600 | |
Remote LDAP Users Sync Rule | 50 | 200 | 1000 | 2000 | 4000 | |
Remote LDAP User Radius Attributes | 1500 | 6000 | 30000 | 60000 | 120000 | |
FSSO & Dynamic Policies | ||||||
FSSO | FSSO Users | 500 | 2000 | 10000 | 20000 | 2000003 |
FSSO Groups | 250 | 1000 | 5000 | 10000 | 20000 | |
Domain Controllers | 10 | 20 | 100 | 200 | 400 | |
RADIUS Accounting SSO Clients | 166 | 666 | 3333 | 6666 | 13333 | |
FortiGate Services | 50 | 200 | 1000 | 2000 | 4000 | |
FortiGate Group Filtering | 250 | 1000 | 5000 | 10000 | 20000 | |
FSSO Tier Nodes | 5 | 20 | 100 | 200 | 400 | |
IP Filtering Rules | 250 | 1000 | 5000 | 10000 | 20000 | |
Accounting Proxy | Sources | 500 | 2000 | 10000 | 20000 | 40000 |
Destinations | 25 | 100 | 500 | 1000 | 2000 | |
Rulesets | 25 | 100 | 500 | 1000 | 2000 | |
Certificates | ||||||
User Certificates | User Certificates | 2500 | 10000 | 50000 | 100000 | 200000 |
Server Certificates | 50 | 200 | 1000 | 2000 | 4000 | |
Certificate Authorities | CA Certificates | 10 | 10 | 50 | 50 | 50 |
Trusted CA Certificates | 200 | 200 | 200 | 200 | 200 | |
Certificate Revocation Lists | 200 | 200 | 200 | 200 | 200 | |
SCEP | Enrollment Requests | 2500 | 10000 | 50000 | 100000 | 200000 |
1 Note that Users is the only metric used for the number of allowed users. Local Users and Remote Users share the same limit value. This enables Local Users or Remote Users to be equal to Users or for there to be a mixture of user types, however, the total number of local and remote users cannot exceed the Users metric.
2 FortiToken Mobile Licenses refers to the licenses that can be applied to a FortiAuthenticator, not the number of FortiToken Mobile instances that can be managed. The total number is limited by the FortiToken metric.
3 For the 3000E, the total number of concurrent SSO users is set to a higher level to cater for large deployments.