Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kredite-ops
New Contributor II

FAC OpenLDAP ldap_search_ext_s search failed: Size limit exceeded

Dear all,

 

In FAC 6.6.4

I'm facing an issue while trying to sync remote LDAP user group with more than 500 user (510 exactly).

The sync rule fails with error Unable to query remote LDAP server SRV_LDAP (ldap.xxx.xxx.xxx.com) for users to sync (rule xxxxxxxxx): ldap_search_ext_s search failed: Size limit exceeded

Is there a way to overcome this limit? 

What are the options to sync and use large LDAP groups?

 

I didn't find anything in the documentation related to ldap group limit size.

 

Thank you all! 

Best Denis

1 Solution
kredite-ops
New Contributor II

We fixed the issue fron OpenLDAP, I got confirmation from Fortinet that there is no limit from FAC PoV.

So we investigate our OpenLDAP setup, and indeed there is a setting olcLimits set to 500, by increasing this to 1000, FAC is able to get up to 1000 user from a sync rule.

 

View solution in original post

6 REPLIES 6
sharmar
Staff
Staff

Hello @kredite-ops 

 

Could you confirm, you have license for how many users on the FAC ?

kredite-ops
New Contributor II

Hello sharma, 

Yes I can confirm that we have licence for 600 users, see screenshot.

 

Best

Denis

Screenshot 2025-08-05 at 09.14.42.png

kredite-ops
New Contributor II

Is there a limitation on FAC regarding the number of users in LDAP group? 

I was also thinking if that could come from our own LDAP server... but I can browse all users in this group using Apache Directory Studio without issue.. 

funkylicious

hi,

as per https://docs.fortinet.com/document/fortiauthenticator/6.6.4/release-notes/917508/maximum-values-for-... , it should be 600 / 10 , therefore 60 users i suppose .

try doing a test with a 61 users group and a 59 users group and see if this is the case.

"jack of all trades, master of none"
"jack of all trades, master of none"
kredite-ops

I have other groups with 200+ users and doesn't have issue with sync rule for them.

So I believe this is not limited with 60 users! 

kredite-ops
New Contributor II

We fixed the issue fron OpenLDAP, I got confirmation from Fortinet that there is no limit from FAC PoV.

So we investigate our OpenLDAP setup, and indeed there is a setting olcLimits set to 500, by increasing this to 1000, FAC is able to get up to 1000 user from a sync rule.

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors