Skip to main content
kredite-ops
New Member
August 4, 2025
Solved

FAC OpenLDAP ldap_search_ext_s search failed: Size limit exceeded

  • August 4, 2025
  • 6 replies
  • 926 views

Dear all,

 

In FAC 6.6.4

I'm facing an issue while trying to sync remote LDAP user group with more than 500 user (510 exactly).

The sync rule fails with error Unable to query remote LDAP server SRV_LDAP (ldap.xxx.xxx.xxx.com) for users to sync (rule xxxxxxxxx): ldap_search_ext_s search failed: Size limit exceeded

Is there a way to overcome this limit? 

What are the options to sync and use large LDAP groups?

 

I didn't find anything in the documentation related to ldap group limit size.

 

Thank you all! 

Best Denis

Best answer by kredite-ops

We fixed the issue fron OpenLDAP, I got confirmation from Fortinet that there is no limit from FAC PoV.

So we investigate our OpenLDAP setup, and indeed there is a setting olcLimits set to 500, by increasing this to 1000, FAC is able to get up to 1000 user from a sync rule.

 

6 replies

sharmar
Staff & Editor
Staff & Editor
August 4, 2025

Hello @kredite-ops 

 

Could you confirm, you have license for how many users on the FAC ?

kredite-ops
New Member
August 5, 2025

Hello sharma, 

Yes I can confirm that we have licence for 600 users, see screenshot.

 

Best

Denis

Screenshot 2025-08-05 at 09.14.42.png

kredite-ops
New Member
August 5, 2025

Is there a limitation on FAC regarding the number of users in LDAP group? 

I was also thinking if that could come from our own LDAP server... but I can browse all users in this group using Apache Directory Studio without issue.. 

funkylicious
SuperUser
SuperUser
August 5, 2025

hi,

as per https://docs.fortinet.com/document/fortiauthenticator/6.6.4/release-notes/917508/maximum-values-for-vm#Maximum%C2%A0values_for_VM:~:text=Remote%20LDAP%20Users%20Sync%20Rule , it should be 600 / 10 , therefore 60 users i suppose .

try doing a test with a 61 users group and a 59 users group and see if this is the case.

"jack of all trades, master of none"
kredite-ops
New Member
August 5, 2025

I have other groups with 200+ users and doesn't have issue with sync rule for them.

So I believe this is not limited with 60 users! 

kredite-ops
kredite-opsAuthorAnswer
New Member
August 6, 2025

We fixed the issue fron OpenLDAP, I got confirmation from Fortinet that there is no limit from FAC PoV.

So we investigate our OpenLDAP setup, and indeed there is a setting olcLimits set to 500, by increasing this to 1000, FAC is able to get up to 1000 user from a sync rule.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.