Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pkay983
New Contributor

Fortigate 7.4.8 LDAP Browse causes firewall to freeze

Hello,

we have a huge active directory with around 99 OUs and many thousand users in it.
If I browse it, my firewall freezes.

I'm only able to create users, by copying the existing ones and change the username. 

 

I can solve it, only query the necessary OUs, but if a User gets moved from one OU to the other, I have to change it every time.

 

I use Server Port 389 / sAMAccountName / Bind Type: regular / Secure Connection / Protokol STARTTLS / no certificate

User Auth. works fine. Problem only occurs when I browse the LDAP

Fortigate is a 200F (no cluster)

Any thoughts?

3 REPLIES 3
funkylicious
SuperUser
SuperUser

hi,

it sounds like the issue would be more related to the size of the AD tree and FortiGate wouldnt be able to perform a query/list all those info.

when you say create users, do you mean to import them locally from AD to FGT ? why would you need that ?

"jack of all trades, master of none"
"jack of all trades, master of none"
Pkay983

On fortigate I add remote LDAP user, search in AD the right one and then user is created.

funkylicious

to what purpose?

maybe this can be achieved just by referincing a LDAP group where users should be present w/o adding them manually.

btw, there's a limit of 100 users that you can add/import/create locally on the FGT, https://docs.fortinet.com/max-value-table search for user.local 

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors