Hi,
I am configuring a Fortigate 100D with Maximum Local Users = 1000
Is there a way to extend that limitation. I can't input anymore users since I reached 1000.
The log in's will be use for SSL VPN clients.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
We are assuming config user local but you could use AD groups mappings.
If this is system admin issues than wildcards "*" would get you more than any hard limits.
PCNSE
NSE
StrongSwan
Agree with emnoc, for such a huge number of users you should authenticate via LDAP/MSAD.
Limits like this are hardcoded, no way to extend them (other than upgrading the hardware).
FG-1000C running v5.2.3 supports 5.000 local users, 350 users per group and 800 user groups.
This is the first FGT to support more than 1.000 local users.
All values from 'Maximum Values List' on docs.fortinet.com.
Happy upgrading. Or get an LDAP server set up. Or a FortiAuthenticator.
We are assuming config user local but you could use AD groups mappings.
If this is system admin issues than wildcards "*" would get you more than any hard limits.
PCNSE
NSE
StrongSwan
Agree with emnoc, for such a huge number of users you should authenticate via LDAP/MSAD.
Limits like this are hardcoded, no way to extend them (other than upgrading the hardware).
emnoc wrote:We are assuming config user local but you could use AD groups mappings.
If this is system admin issues than wildcards "*" would get you more than any hard limits.
Yup, but the client has no LDAP. He requires to encode 5000 users...
"If this is system admin issues than wildcards "*" would get you more than any hard limits."
@emnoc what you mean by this?
Yup, but the client has no LDAP. He requires to encode 5000 users... "If this is system admin issues than wildcards "*" would get you more than any hard limits." @emnoc what you mean by this?
So if he has 5K users you really need to run LDAP and uses ad groups or get a bigger FGT model.
The FGT100D is not really a enterprise FW applianes. I believe you need a 3K series or higher if you need more than 1K users for local users. Maybe they have bump the max values in 5.4x but I higher doubt it.
Keep in mind managing local users on a appliance 1> is time consuming 2> more issues 3> more over head 4> and you can't really do MFA with email/sms with just groups matches
"If this is system admin issues than wildcards "*" would get you more than any hard limits." @emnoc what you mean by this?
On my last part, if you are needing "sys admin" accounts you are stuck at 30) users or less so "wildcards" authentication to a remote-auth like RADIUS/TACACS+/LDAP/etc... will get you above 300 users.
Ken
PCNSE
NSE
StrongSwan
FG-1000C running v5.2.3 supports 5.000 local users, 350 users per group and 800 user groups.
This is the first FGT to support more than 1.000 local users.
All values from 'Maximum Values List' on docs.fortinet.com.
Happy upgrading. Or get an LDAP server set up. Or a FortiAuthenticator.
Good job I was to lazy to look at the max values. I could have swore it was 3K at minimum. It looks likes FTNT has finally realize they need to update the 1K local users value.
:)
PCNSE
NSE
StrongSwan
But really, 5.000 local users, managed on a Fortigate?? (I was too lazy for this rant yesterday...)
Looks like the FGT for a small ISP, or a medium sized company with a lot of travelling salesmen. In any case, this is enterprise turf, and I just don't get it why they don't (want to) use Directory services like LDAP.
If you set up LDAP in a VM, you can easily bulid a redundant, fail-safe instance on which to rely on. Imagine the FGT was down - no further authentication possible.
Another advantage of LDAP is that you can put the same user into different user groups, for remote access, firewall identity based rules, access to internal resources, whatever. The FGT cannot cover all these cases.
OK, enough for today.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.