- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
User restrictions Fortigate D30 Local and LDAP users
I have about 40 LDAP and 10 Local user on a fortigate 30e added.
If I want to add more user the output is as follow:
reached the maximum number of entries On the data sheet are no restrictions as i can see.
https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_FortiWiFi_30E.pdf
If somebody know something would be great. Thanks in advance
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Each device has its limits. This can be found here: [link]https://docs.fortinet.com/max-value-table[/link] or directly on the device by running this CLI command: print tablesize The limit for FWF30E is 50 for user.local > which is table for ldap+local users There is no going above these limits even with VDOMs Instead of importing users directly, can you import the ldap group(s)?
That is if you do not plan to use fortitokens for each user.
Best Regards,
Alivo
livo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Each device has its limits. This can be found here: [link]https://docs.fortinet.com/max-value-table[/link] or directly on the device by running this CLI command: print tablesize The limit for FWF30E is 50 for user.local > which is table for ldap+local users There is no going above these limits even with VDOMs Instead of importing users directly, can you import the ldap group(s)?
That is if you do not plan to use fortitokens for each user.
Best Regards,
Alivo
livo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for this fast respond, this is really helpful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I use the Fortitoken (two mobile tockens to be precise) for the two factor authentification. So i gues with that i stuck, because it seams i can't allocate the phonenumbers to the user when i use the remote group.
Can u approve that or is there a workaround?
Thank you in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im Looking already for a bigger firewall up to 1000 user.local but in the data sheets i can't find any information about it. May you know where i can get this information?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Davu,
Thank you for feedback. I found FortiGate 100E with 1000 local users. You can check out FortiAuthenticator too: https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiAuthenticator.pdf I should also add, that some limits are per VDOM. This means that the limit can be per vdom. 1st vdom 500 users, 2nd vdom 500 users, 3rd vdom another 500 users etc... > 10 vdoms 500 user each > 5000 users. This may not be always useful as it bears other implications such as configuring new subnets and more.
The limits are further explained here: https://kb.fortinet.com/kb/documentLink.do?externalID=FD40371 Best Regards,
Alivo
livo
