Skip to main content
rvijayaraj
Staff
Staff
March 10, 2026

Technical Tip: FortiAuthenticator does not sync the LDAP Tree in Load Balancing mode

  • March 10, 2026
  • 0 replies
  • 143 views
Description This article describes why the LDAP Tree does not sync between the FortiAuthenticator nodes configured in Load Balancing mode.
Scope FortiAuthenticator.
Solution

FortiAuthenticator can be configured in two different clustering modes:

  1. Active-Passive.
  2. Load-Balancing.

 

The images below show the results of the FortiAuthenticator configured in Load-Balancing mode, and the LDAP Tree not syncing between them.

 

Status of HA:

 
 

FAC1.png

 

FAC2.png

 

User info synced between the devices. 

 

FAC1_Users.png

 

FAC2_Users.png

 

The LDAP tree shows only on the (standalone) primary device, not on the load-balancing node:

 

FAC1_LDAP_Tree.png

 

FAC2_LDAP_Tree.png

 

This is an expected behavior since the LDAP Tree and related settings are not synced in a load-balancing setup.

Related articles: