Skip to main content
kgurbuz
Staff
Staff
July 14, 2026

Troubleshooting Tip: LDAP authentication failure via FortiAuthenticator and FortiIdentity Cloud using Zero Trust Tunnel (ZTNA TCP forwarding) on FortiGate

  • July 14, 2026
  • 0 replies
  • 217 views

Description

This article describes a known issue for LDAP authentication failure when using Zero Trust Tunnel on FortiAuthenticator and FortiIdentity Cloud via FortiGate ZTNA TCP Forwarding.

Scope

FortiGate, FortiAuthenticator, FortiIdentity Cloud. Affected firmware versions: FortiOS v7.6, v7.4, and v7.2.11.

Solution

Users may experience LDAP authentication failures when using FortiAuthenticator (FAC) and FortiIdentity Cloud with Zero Trust Network Access (ZTNA) TCP forwarding on FortiGate.

The authentication process remains in a PENDING state and fails with the error message 'Can't contact LDAP server', even though the ZTNA tunnel is established, and traffic is hitting the FortiGate policy. The LDAP bind does not complete, and the issue is confirmed to be on the FortiGate, not the FortiAuthenticator.

Affected firmware versions: FortiOS v7.6, v7.4, and v7.2.11. v7.2.10 was not affected by this bug.

FortiAuthenticator v6.6 branch:

This issue is due to a known FortiGate issue with ID 1197955 affecting LDAP authentication over ZTNA TCP forwarding. The known issue prevents successful LDAP queries or real server connections when using a FortiAuthenticator jump server through a ZTNA tunnel.

Upgrade the FortiGate to FortiOS v7.6.7 or later, or FortiOS v8.0.0 or later.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!