Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
icankil
New Contributor

Fortigate Maximum Local Users, extension?

Hi,

 

I am configuring a Fortigate 100D with Maximum Local Users = 1000

Is there a way to extend that limitation. I can't input anymore users since I reached 1000.

The log in's will be use for SSL VPN clients.

 

 

 

 

 

 

 

 

 

3 Solutions
emnoc
Esteemed Contributor III

We are assuming config user local  but you could use AD groups mappings.

 

If this is system admin issues than wildcards "*" would get you more than any hard limits.

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
ede_pfau

Agree with emnoc, for such a huge number of users you should authenticate via LDAP/MSAD.

Limits like this are hardcoded, no way to extend them (other than upgrading the hardware).


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
ede_pfau

FG-1000C running v5.2.3 supports 5.000 local users, 350 users per group and 800 user groups.

This is the first FGT to support more than 1.000 local users.

 

All values from 'Maximum Values List' on docs.fortinet.com.

 

Happy upgrading. Or get an LDAP server set up. Or a FortiAuthenticator.


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
7 REPLIES 7
emnoc
Esteemed Contributor III

We are assuming config user local  but you could use AD groups mappings.

 

If this is system admin issues than wildcards "*" would get you more than any hard limits.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau

Agree with emnoc, for such a huge number of users you should authenticate via LDAP/MSAD.

Limits like this are hardcoded, no way to extend them (other than upgrading the hardware).


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
icankil
New Contributor

emnoc wrote:

We are assuming config user local  but you could use AD groups mappings.

 

If this is system admin issues than wildcards "*" would get you more than any hard limits.

 

 

 

Yup, but the client has no LDAP. He requires to encode 5000 users...

 

"If this is system admin issues than wildcards "*" would get you more than any hard limits."

@emnoc what you mean by this?

 

 

emnoc
Esteemed Contributor III

Yup, but the client has no LDAP. He requires to encode 5000 users...   "If this is system admin issues than wildcards "*" would get you more than any hard limits." @emnoc what you mean by this?

 

 

So if he has  5K users you really need to run  LDAP and uses ad groups or  get a bigger  FGT model.

 

The FGT100D is not really a enterprise  FW applianes. I believe you need a 3K series or higher if you need more than 1K users for local users. Maybe they have bump the max values in 5.4x but I higher doubt it.

 

Keep in mind managing  local users on a appliance 1> is time consuming 2> more issues 3> more over head 4> and you can't really do MFA with email/sms with just groups matches

 

"If this is system admin issues than wildcards "*" would get you more than any hard limits." @emnoc what you mean by this?

 

 

 

On my  last part, if you are needing "sys admin" accounts you are stuck at 30) users or less so "wildcards" authentication to a remote-auth like RADIUS/TACACS+/LDAP/etc... will get you above 300 users.

 

Ken

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau

FG-1000C running v5.2.3 supports 5.000 local users, 350 users per group and 800 user groups.

This is the first FGT to support more than 1.000 local users.

 

All values from 'Maximum Values List' on docs.fortinet.com.

 

Happy upgrading. Or get an LDAP server set up. Or a FortiAuthenticator.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
emnoc
Esteemed Contributor III

Good job I was to lazy to look at the max values. I could have swore it was  3K at minimum. It looks likes  FTNT has finally realize they need to update the 1K local users value.

 

:)

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau

But really, 5.000 local users, managed on a Fortigate?? (I was too lazy for this rant yesterday...)

Looks like the FGT for a small ISP, or a medium sized company with a lot of travelling salesmen. In any case, this is enterprise turf, and I just don't get it why they don't (want to) use Directory services like LDAP.

If you set up LDAP in a VM, you can easily bulid a redundant, fail-safe instance on which to rely on. Imagine the FGT was down - no further authentication possible.

Another advantage of LDAP is that you can put the same user into different user groups, for remote access, firewall identity based rules, access to internal resources, whatever. The FGT cannot cover all these cases.

 

OK, enough for today.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors