Skip to main content
nverma
Staff
Staff
July 26, 2022

Technical Tip: How to refresh/clear the wad user/group cache on FortiProxy v7.0.x

  • July 26, 2022
  • 0 replies
  • 5307 views
Description This article describes how to refresh/clear the wad user/group cache on FortiProxy v7.0.x.
Scope FortiProxy v7.0.x.
Solution

As wad maintains its cache for user & group information.

 

In firmware v7.0.x, the old command to refresh/clear the WAD user/group cache does not exist.

 

Clear the existing user cache using the following CLI commands:

 

diagnose wad user clear <ID> <IP> <VDOM>

 

Once the user is deauthenticated, run the commands below to refresh/clear the WAD cache.


diagnose test app wad 2500
diagnose test app wad

 

160: clear cached user info mapping table
161: trigger user cache refreshing
162: trigger group cache refreshing

 

After the cache is cleared and the user is authenticated, the updated user info with the correct group will be reflected.


Also, choose to disable the cache globally for LDAP users as a workaround using the below configuration.

 

config web-proxy global

    set ldap-user-cache disable

end

 

Enable: LDAP auth is done by WAD user-info.
Disable: LDAP auth is done by fnbamd.


Note that the 'ldap-user-cache' option only works with Windows AD. For any other vendors like the Novel e-directory LDAP server, the 'ldap-user-cache' option should be disabled.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!