Hello,
we have a huge active directory with around 99 OUs and many thousand users in it.
If I browse it, my firewall freezes.
I'm only able to create users, by copying the existing ones and change the username.
I can solve it, only query the necessary OUs, but if a User gets moved from one OU to the other, I have to change it every time.
I use Server Port 389 / sAMAccountName / Bind Type: regular / Secure Connection / Protokol STARTTLS / no certificate
User Auth. works fine. Problem only occurs when I browse the LDAP
Fortigate is a 200F (no cluster)
Any thoughts?
hi,
it sounds like the issue would be more related to the size of the AD tree and FortiGate wouldnt be able to perform a query/list all those info.
when you say create users, do you mean to import them locally from AD to FGT ? why would you need that ?
On fortigate I add remote LDAP user, search in AD the right one and then user is created.
to what purpose?
maybe this can be achieved just by referincing a LDAP group where users should be present w/o adding them manually.
btw, there's a limit of 100 users that you can add/import/create locally on the FGT, https://docs.fortinet.com/max-value-table search for user.local
| User | Count |
|---|---|
| 2730 | |
| 1417 | |
| 812 | |
| 739 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.