Skip to main content
davu
New Member
March 22, 2021
Solved

User restrictions Fortigate D30 Local and LDAP users

  • March 22, 2021
  • 1 reply
  • 5281 views

I have about 40 LDAP and 10 Local user on a fortigate 30e added.

If I want to add more user the output is as follow:

 

reached the maximum number of entries On the data sheet are no restrictions as i can see.

https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_FortiWiFi_30E.pdf

 

If somebody know something would be great. Thanks in advance

    Best answer by Alivo__FTNT

    Hello,

     

    Each device has its limits. This can be found here: [link]https://docs.fortinet.com/max-value-table[/link] or directly on the device by running this CLI command: print tablesize The limit for FWF30E is 50 for user.local > which is table for ldap+local users There is no going above these limits even with VDOMs Instead of importing users directly, can you import the ldap group(s)?

    That is if you do not plan to use fortitokens for each user.

    Best Regards,

    Alivo

    1 reply

    Alivo__FTNT
    Staff
    Staff
    March 23, 2021

    Hello,

     

    Each device has its limits. This can be found here: [link]https://docs.fortinet.com/max-value-table[/link] or directly on the device by running this CLI command: print tablesize The limit for FWF30E is 50 for user.local > which is table for ldap+local users There is no going above these limits even with VDOMs Instead of importing users directly, can you import the ldap group(s)?

    That is if you do not plan to use fortitokens for each user.

    Best Regards,

    Alivo

    davu
    davuAuthor
    New Member
    March 23, 2021

    Thank you for this fast respond, this is really helpful.

    davu
    davuAuthor
    New Member
    March 23, 2021

    I use the Fortitoken (two mobile tockens to be precise) for the two factor authentification. So i gues with that i stuck, because it seams i can't allocate the phonenumbers to the user when i use the remote group.

    Can u approve that or is there a workaround?

    Thank you in advance.