Skip to main content
aionescu
Staff
Staff
November 6, 2024

Technical Tip: How to change the LDAP user and group cache update times on FortiGate

  • November 6, 2024
  • 0 replies
  • 1373 views
Description

This article describes how to change the LDAP user and group cache on FortiGate configured as explicit proxy.

Scope FortiGate v7.4.2+
Solution

Starting with v7.4.2 the following commands were introduced:

 

diagnose debug enable
diagnose test app wad 250

diagnose test application wad 1900xyz <----- Change the user cache time (xyz=minutes).
diagnose test application wad 1910xyz <----- Change the Group cache time (xyz=minutes).

 

The example below changes the user and group timers from default 1440 to 10 minutes:

 

get system status
Version: FortiGate-VM64-KVM v7.4.2,build2571,231219 (GA.F)

diag test app wad 1900010
Change user cache flushing timeout from: 1400 to 10

diag test app wad 1910010
Change group cache flushing timeout from: 1400 to 10

 

Note:

By default, the cache refresh interval is set to 24 hours (1400 minutes), and, in environments where there are frequent changes, a lower value might be needed.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!