When enabling the Explicit Proxy feature on a FortiGate 40F(ver6.4.11) and performing several thousand Kerberos authentication tests from a test tool, 1001 users appeared in the authentication list on the web management console, but no additional users were shown beyond that.
We had not considered the configuration or limitations regarding the number of concurrent authentications, so we researched the related settings and found the following website.
When we checked the configuration on the tested FortiGate, the value of "policy-auth-concurrent" was set to 0.
So far, we have not been able to obtain information on the maximum number of concurrent authentications possible.
Please tell me the maximum number of concurrent authenticated users supported by FortiGate.
If the maximum number of concurrent authenticated users varies by device model, I would like to know how to check the maximum number of concurrent authenticated users for each model.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Usually, if the value is not listed in the max values table or documented elsewhere, the limitation is dictated by the amount of resources available at that moment, in that unit (memory). Also to consider that display issues may arise for high numbers, so for performance optimization, in GUI the results might be limited to a certain amount of characters, or time to load the page.
Is there actually a problem that you are facing?
Because if you are simply testing, I would suggest to use one of the supported firmware versions (7.0+)
Hi,
Max values for a model on a specific firmware could be found here docs.fortinet.com/max-value-table
You could also find some info regarding the same here Technical Note: FortiGate maximum values ... - Fortinet Community
Best regards,
Jin
Thank you for your response.
I would like to know the maximum number of users that can simultaneously perform Kerberos authentication on FortiGate when used as a proxy.
Could you please tell me the name of the parameter where this value is configured?
Usually, if the value is not listed in the max values table or documented elsewhere, the limitation is dictated by the amount of resources available at that moment, in that unit (memory). Also to consider that display issues may arise for high numbers, so for performance optimization, in GUI the results might be limited to a certain amount of characters, or time to load the page.
Is there actually a problem that you are facing?
Because if you are simply testing, I would suggest to use one of the supported firmware versions (7.0+)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.