Skip to main content
rmharini
Staff
Staff
December 15, 2024

Technical Tip: Username format used to connect to the SSL VPN when two LDAP servers are configured on FortiAuthenticator

  • December 15, 2024
  • 0 replies
  • 480 views
Description This article describes the username format required to connect to the SSL VPN when two LDAP servers are configured on FortiAuthenticator.
Scope FortiAuthenticator.
Solution

When two LDAP servers are configured on the FortiAuthenticator, users from LDAP Group 1 can connect to the SSL VPN using only their username, while users from LDAP Group 2 must use the 'Username format' specified in the RADIUS policy.

 

Examples:

  • LDAP Server 1: Users connecting to LDAP Group 1 via SSL VPN log in using just the username. For example test.

  • LDAP Server 2: Users connecting to LDAP Group 2 via SSL VPN must log in using the 'realm\username' format as specified in the RADIUS policy. For example: ldap_2\test2.

LDAP Server 1 and LDAP Server 2 are distinct and separate servers.

 

ldap-server2.png

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!