Troubleshooting Tip: LDAP authentication failure using MFA even with the right user and password on SSL VPN web access
| Description | This article describes the behavior related to the LDAP authentication failure using the FortiToken as MFA, even if the user and password are correct. |
| Scope | FortiGate up to v7.6.2, SSL VPN web access, FortiToken, LDAP user added on the FortiGate (Not FSSO). |
| Solution | After running the following CLI command:
When it works as expected, there is a line:
When the issue happens and there is a line:
But the credentials are unquestionable, it is required to check the account on the Active Directory, because the FortiGate does not handle the account management, like password expiration. A recommendation is to reset the password and uncheck the option for the user to change the password on the next logon, if it is the case of a password issue on the account.
Related article: |
