Querying the same remote LDAP servers via FortiGate and FortiAuthenticator (FAC)
Hi everyone,
On my FortiGate running v7.4.9, I have a specific VDOM configured for one of my clients.
Currently, this VDOM is integrated with a FortiAuthenticator (FAC), which in turn queries two remote LDAP servers to handle MFA for client VPNs.
Â
I now need to configure these same two remote LDAP servers directly on the FortiGate (under User & Authentication -> LDAP Servers) so I can use Active Directory groups in our firewall policies.
Â
I would like to know if there are any specific best practices to follow, and I have a couple of questions:
Â
LDAP Query Load: Are these two remote LDAP servers at risk of being overloaded with too many queries due to this dual integration (FAC for VPN + FortiGate direct for security policies) ?
Â
Cache Management: Would you recommend enabling and tuning the cache on the FortiGate (increasing `set cache-ttl` to 300 or higher) ?
If so, what is your recommended value for a production environment ?
Â
Thanks in advance to everyone for any advice or insights !
