Maximum Values Table
The values in this table are the hard-coded maximum values. As such, they might not be practical limits for every situation and are not a promise of performance.
NOTE: To list the complete maximum values for your FortiProxy unit, use the print tablesize
CLI command.
In the following table, the table-instance limit means the maximum number of entries in each table instance, and the global limit means the maximum number of entries over all tables of the same type within the system. 0 indicates “unlimited.”
The default values for any primary table not listed in the following table are:
- Table-instance limit: 0
- Global limit: 512
The default values for any secondary table not listed in the following table are:
- Table-instance limit: 0
- Global limit: 0
Object Name |
400E |
VM8 | 2000E VM16 VMUL |
4000E |
---|---|---|---|---|
system.zone
|
0 0 |
0 0 |
0 0 |
0 0 |
system.zone:interface
|
0 0 |
0 0 |
0 0 |
0 0 |
system.interface
|
0 8192 |
0 8192 |
0 8192 |
0 8192 |
system.interface:secondaryip
|
32 0 |
32 0 |
32 0 |
32 0 |
system.interface:ipv6:ip6-prefix-list
|
32 0 |
32 0 |
32 0 |
32 0 |
system.interface:dhcp-snooping-server-list
|
255 2048 |
255 2048 |
255 2048 |
255 2048 |
system.accprofile
|
0 16 |
0 64 |
0 64 |
0 64 |
system.admin
|
0 300 |
0 300 |
0 300 |
0 300 |
system.snmp.community
|
0 3 |
0 3 |
0 3 |
0 3 |
system.snmp.community:hosts
|
16 0 |
16 0 |
16 0 |
16 0 |
system.snmp.community:hosts6
|
16 0 |
16 0 |
16 0 |
16 0 |
system.snmp.user
|
0 32 |
0 32 |
0 32 |
0 32 |
system.session-ttl:port
|
0 0 |
0 0 |
0 0 |
0 0 |
system.dhcp.server
|
0 0 |
0 0 |
0 0 |
0 0 |
system.dhcp.server:options
|
30 0 |
30 0 |
30 0 |
30 0 |
system.dhcp.server:reserved-address
|
0 0 |
0 0 |
0 0 |
0 0 |
system.dhcp.server:ip-range
|
3 0 |
3 0 |
3 0 |
3 0 |
system.dhcp.server:exclude-range
|
16 0 |
16 0 |
16 0 |
16 0 |
system.mac-address-table
|
0 0 |
0 0 |
0 0 |
0 0 |
system.arp-table
|
0 10240 |
0 16834 |
0 16834 |
0 16834 |
system.proxy-arp
|
0 0 |
0 0 |
0 0 |
0 0 |
system.tos-based-priority
|
0 0 |
0 0 |
0 0 |
0 0 |
system.dscp-based-priority
|
0 0 |
0 0 |
0 0 |
0 0 |
system.replacemsg-group
|
0 0 |
0 0 |
0 0 |
0 0 |
system.central-management:server-list
|
100 0 |
100 0 |
100 0 |
100 0 |
system.replacemsg-image
|
0 21 |
0 21 |
0 21 |
0 21 |
system.saml:service-providers:assertion-attributes
|
4 0 |
4 0 |
4 0 |
4 0 |
system.dns:server-hostname
|
4 0 |
4 0 |
4 0 |
4 0 |
system.ddns:ddns-server-ip
|
4 0 |
4 0 |
4 0 |
4 0 |
system.dns-database
|
0 0 |
0 0 |
0 0 |
0 0 |
user.radius
|
0 0 |
0 0 |
0 0 |
0 0 |
user.pop3
|
0 0 |
0 0 |
0 0 |
0 0 |
user.radius:accounting-server
|
4 0 |
4 0 |
4 0 |
4 0 |
user.tacacs+
|
0 0 |
0 0 |
0 0 |
0 0 |
user.ldap
|
0 0 |
0 0 |
0 0 |
0 0 |
user.saml
|
0 0 |
0 0 |
0 0 |
0 0 |
user.fortitoken
|
0 1000 |
0 1000 |
0 5000 |
0 5000 |
user.local
|
0 0 |
0 0 |
0 0 |
0 0 |
user.peer
|
0 0 |
0 0 |
0 0 |
0 0 |
user.peergrp
|
0 0 |
0 0 |
0 0 |
0 0 |
user.peergrp:member
|
50000 0 |
50000 0 |
50000 0 |
50000 0 |
user.adgrp
|
0 1024 |
0 1024 |
0 8192 |
0 8192 |
user.fsso-polling:adgrp
|
0 0 |
0 0 |
0 0 |
0 0 |
user.group
|
0 0 |
0 0 |
0 0 |
0 0 |
user.group:member
|
3000 0 |
3000 0 |
3000 0 |
3000 0 |
user.group:guest
|
500 0 |
1024 0 |
1024 0 |
1024 0 |
system.ips-urlfilter-dns
|
0 20 |
0 20 |
0 20 |
0 20 |
system.ips-urlfilter-dns6
|
0 20 |
0 20 |
0 20 |
0 20 |
webfilter.ftgd-local-cat
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.address
|
0 20000 |
0 40000 |
0 100000 |
0 100000 |
firewall.address6
|
0 20000 |
0 40000 |
0 100000 |
0 100000 |
firewall.wildcard-fqdn.custom
|
0 512 |
0 512 |
0 512 |
0 512 |
firewall.wildcard-fqdn.group
|
0 512 |
0 512 |
0 512 |
0 512 |
firewall.proxy-address
|
0 2048 |
02 8192 |
0 8192 |
0 8192 |
firewall.service.custom
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.service.group
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.service.group:member
|
300 0 |
300 0 |
300 0 |
300 0 |
firewall.schedule.onetime
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.schedule.recurring
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.ippool
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.profile-group
|
0 500 |
0 1000 |
0 20000 |
0 20000 |
firewall.profile-protocol-options
|
0 500 |
0 500 |
0 500 |
0 500 |
firewall.ssl-ssh-profile
|
0 500 |
0 500 |
0 500 |
0 500 |
firewall.ssl-ssh-profile:ssl-exempt
|
255 0 |
255 0 |
255 0 |
255 0 |
firewall.vip
|
0 16384 |
0 32768 |
0 32768 |
0 32768 |
firewall.vip:monitor
|
5 5 |
5 5 |
5 5 |
5 5 |
firewall.vip:realservers
|
16 0 |
64 0 |
256 0 |
256 0 |
firewall.vip:realservers:monitor
|
5 5 |
5 5 |
5 5 |
5 5 |
firewall.vipgrp
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.vipgrp:member
|
500 0 |
500 0 |
500 0 |
500 0 |
firewall.ipmacbinding.table
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.addrgrp
|
0 2500 |
0 20000 |
0 20000 |
0 20000 |
firewall.addrgrp6
|
0 2500 |
0 20000 |
0 20000 |
0 20000 |
firewall.addrgrp:member
|
600 0 |
1500 0 |
0 0 |
0 0 |
firewall.proxy-addrgrp
|
0 1024 |
0 4096 |
0 4096 |
0 4096 |
firewall.proxy-addrgrp:member
|
300 0 |
1500 0 |
1500 0 |
1500 0 |
firewall.ssh.host-key
|
2000 0 |
2000 0 |
2000 0 |
2000 0 |
firewall.ssh.local-key
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.ssh.local-ca
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.policy
|
0 10000 |
0 100000 |
0 200000 |
0 200000 |
firewall.policy:custom-log-fields
|
5 0 |
5 0 |
5 0 |
5 0 |
firewall.policy:poolname
|
64 0 |
64 0 |
64 0 |
64 0 |
firewall.vip6
|
0 16384 |
0 32768 |
0 32768 |
0 32768 |
firewall.vip6:monitor
|
5 5 |
5 5 |
5 5 |
5 5 |
firewall.vip6:realservers
|
8 0 |
32 0 |
32 0 |
32 0 |
firewall.vip6:realservers:monitor
|
5 5 |
5 5 |
5 5 |
5 5 |
firewall.vipgrp6
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.vipgrp6:member
|
500 0 |
500 0 |
500 0 |
500 0 |
firewall.central-snat-map
|
0 1024 |
0 30000 |
0 30000 |
0 30000 |
firewall.internet-service-addition:entry:port-range
|
0 64 |
0 64 |
0 64 |
0 64 |
firewall.service.category
|
0 500 |
0 5000 |
0 10000 |
0 10000 |
wanopt.profile
|
0 0 |
0 0 |
0 0 |
0 0 |
wanopt.peer
|
0 0 |
0 0 |
0 0 |
0 0 |
wanopt.auth-group
|
0 0 |
0 0 |
0 0 |
0 0 |
wanopt.ssl-server
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.ldb-monitor
|
0 0 |
0 0 |
0 0 |
0 0 |
firewall.shaper.traffic-shaper
|
0 0 |
0 0 |
0 0 |
0 0 |
vpn.ssl.web.portal
|
0 0 |
0 2600 |
0 2600 |
0 2600 |
vpn.ssl.web.portal:bookmark-group:bookmarks
|
256 0 |
256 0 |
256 0 |
256 0 |
vpn.ssl.web.user-group-bookmark
|
0 500 |
0 2600 |
0 2600 |
0 2600 |
vpn.ssl.web.user-group-bookmark:bookmarks
|
128 0 |
128 0 |
128 0 |
128 0 |
vpn.ssl.web.user-bookmark:bookmarks
|
128 0 |
128 0 |
128 0 |
128 0 |
ips.custom
|
0 256 |
0 256 |
0 1000 |
0 1000 |
router.static
|
0 0 |
0 0 |
0 0 |
0 0 |
router.policy
|
0 512 |
0 2048 |
0 2048 |
0 2048 |
router.static6
|
0 0 |
0 0 |
0 0 |
0 0 |
vpn.certificate.local
|
0 0 |
0 0 |
0 0 |
0 0 |
vpn.certificate.ca
|
0 0 |
0 0 |
0 0 |
0 0 |
vpn.certificate.crl
|
0 0 |
0 0 |
0 0 |
0 0 |
system.gre-tunnel
|
0 0 |
0 0 |
0 0 |
0 0 |
system.vxlan
|
0 0 |
0 0 |
0 0 |
0 0 |
vpn.ipsec.phase1-interface
|
0 0 |
0 0 |
0 0 |
0 0 |
vpn.ipsec.phase2-interface
|
0 0 |
0 0 |
0 0 |
0 0 |
webfilter.ftgd-local-rating
|
0 0 |
0 0 |
0 0 |
0 0 |
application.list
|
0 256 |
0 256 |
0 1000 |
0 1000 |
application.custom
|
0 0 |
0 0 |
0 0 |
0 0 |
application.casi.profile
|
0 256 |
0 256 |
0 1000 |
0 1000 |
ips.sensor
|
0 256 |
0 256 |
0 1000 |
0 1000 |
ips.sensor:override:exempt-ip
|
8 0 |
8 0 |
8 0 |
8 0 |
webfilter.profile
|
0 500 |
0 1000 |
0 20000 |
0 20000 |
webfilter.profile:web:keyword-match
|
0 0 |
0 0 |
0 0 |
0 0 |
webfilter.content
|
0 0 |
0 0 |
0 0 |
0 0 |
webfilter.content:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
webfilter.exmword
|
0 0 |
0 0 |
0 0 |
0 0 |
webfilter.exmword:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
webfilter.urlfilter
|
0 256 |
0 256 |
0 1000 |
0 1000 |
webfilter.urlfilter:entries
|
0 32000 |
0 32000 |
0 250000 |
0 250000 |
webfilter.override
|
0 0 |
0 0 |
0 0 |
0 0 |
dnsfilter.profile
|
0 32 |
0 32 |
0 500 |
0 500 |
dnsfilter.domain-filter
|
0 32 |
0 32 |
0 256 |
0 256 |
dnsfilter.profile:domain-filter:external-blocklist
|
10 0 |
10 0 |
10 0 |
10 0 |
dnsfilter.domain-filter:entries
|
0 32000 |
0 32000 |
0 250000 |
0 250000 |
emailfilter.profile
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.bword
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.block-allow-list
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.dnsbl
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.iptrust
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.mheader
|
0 0 |
0 0 |
0 0 |
0 0 |
antivirus.profile
|
0 0 |
0 0 |
0 0 |
0 0 |
antivirus.contenttype
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.bword:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.block-allow-list:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.dnsbl:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.iptrust:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
emailfilter.mheader:entries
|
0 0 |
0 0 |
0 0 |
0 0 |
dlp.filepattern:entries
|
32000 0 |
32000 0 |
250000 0 |
250000 0 |
dlp.filepattern
|
0 1000 |
0 5000 |
0 12500 |
0 12500 |
dlp.sensor
|
0 64 |
0 1000 |
0 1500 |
0 1500 |
dlp.sensor:filter
|
2000 0 |
3000 0 |
4000 0 |
4000 0 |
dlp.sensitivity
|
0 0 |
0 0 |
0 0 |
0 0 |
file-filter.profile
|
0 64 |
0 1000 |
0 1500 |
0 1500 |
file-filter.profile:rules
|
2000 0 |
3000 0 |
4000 0 |
4000 0 |
report.layout
|
0 0 |
0 0 |
0 0 |
0 0 |
report.layout:body-item
|
256 0 |
256 0 |
256 0 |
256 0 |
report.layout:page:header:header-item
|
2 0 |
2 0 |
2 0 |
2 0 |
report.layout:page:footer:footer-item
|
2 0 |
2 0 |
2 0 |
2 0 |
user.fsso
|
0 0 |
0 0 |
0 0 |
0 0 |
user.fsso-polling
|
0 20 |
0 100 |
0 100 |
0 100 |
log.threat-weight:geolocation
|
0 0 |
0 0 |
0 0 |
0 0 |
log.threat-weight:web
|
0 0 |
0 0 |
0 0 |
0 0 |
log.threat-weight:application
|
0 0 |
0 0 |
0 0 |
0 0 |
log.setting:custom-log-fields
|
5 0 |
5 0 |
5 0 |
5 0 |
system.automation-trigger:fields
|
5 0 |
5 0 |
5 0 |
5 0 |
ssh-filter.profile:shell-commands
|
256 0 |
256 0 |
256 0 |
256 0 |
endpoint-control.fctems
|
0 3 |
0 3 |
0 3 |
0 3 |
system.object-tagging
|
0 1024 |
0 4096 |
0 4096 |
0 4096 |
system.ha:ha-mgmt-interfaces
|
0 4 |
0 4 |
0 4 |
0 4 |
system.ha:unicast-peers
|
0 7 |
0 7 |
0 7 |
0 7 |
system.sdn-connector
|
0 16 |
0 16 |
0 16 |
0 16 |
log.fortianalyzer.setting:serial
|
8 0 |
8 0 |
8 0 |
8 0 |
log.fortianalyzer2.setting:serial
|
8 0 |
8 0 |
8 0 |
8 0 |
log.fortianalyzer3.setting:serial
|
8 0 |
8 0 |
8 0 |
8 0 |
log.fortianalyzer.override-setting:serial
|
8 0 |
8 0 |
8 0 |
8 0 |
log.fortianalyzer2.override-setting:serial
|
8 0 |
8 0 |
8 0 |
8 0 |
log.fortianalyzer3.override-setting:serial
|
8 0 |
8 0 |
8 0 |
8 0 |
system.sso-admin
|
0 300 |
0 300 |
0 550 |
0 550 |
firewall.internet-service-name
|
0 8192 |
0 8192 |
0 8192 |
0 8192 |
system.sso-forticloud-admin
|
0 300 |
0 300 |
0 550 |
0 550 |
system.nethsm:servers
|
0 2 |
0 2 |
0 2 |
0 2 |
system.nethsm:slots
|
0 10 |
0 10 |
0 10 |
0 10 |
system.nethsm:hagroups
|
0 2 |
0 2 |
0 2 |
0 2 |