Skip to main content
nevan
Staff
Staff
August 19, 2025

Technical Tip: Understanding 'user-device-store-max-unified-mem' in FortiGate

  • August 19, 2025
  • 0 replies
  • 594 views
Description

This article describes the feature "user-device-store-max-unified-mem' available under 'config system global' in FortiOS, which maintains an internal database to keep track of user logins, device identities, and related session information.

This parameter is being used so that this tracking does not consume excessive system resources, and the administrators can set memory usage limits.

Scope FortiGate.
Solution

The 'user-device-store-max-unified-mem' is a system global setting that defines the maximum amount of memory the user device store can utilize. By capping the allocated memory, FortiGate prevents device and user information from overwhelming system resources, which is particularly important on hardware models with limited memory.

This parameter works alongside other limits, such as:

  • user-device-store-max-users: maximum number of users that can be stored.

  • user-device-store-max-devices: maximum number of devices that can be stored.

 

The values are important to user-based firewall policies, device-based security profiles, and IP-to-user and device mappings.

CLI:


config system global
     set user-device-store-max-unified-mem <value>
     set user-device-store-max-users <value>
     set user-device-store-max-devices <value>
 end

 

The values can vary depending on versions. To get the minimum, maximum, and default values, check the CLI reference guide from the Document Library of FortiGate.

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!