Skip to main content
cmaheu
Staff
Staff
April 13, 2022

Technical Tip: Removal/Addition of LDAP model can cause user synchronization issues.

  • April 13, 2022
  • 0 replies
  • 761 views
Description

This article describes a behavior where user attribute information is no longer accurate after adding and removing LDAP directory models. Some user records can still be associated to the old directory.

This prevents information from updating properly when a directory synchronization is run.

 

Symptoms include hosts not matching policies based on LDAP group membership.

 

For instructions to replace a directory, refer to the following link:
https://docs.fortinet.com/document/fortinac/9.4.0/administration-guide/956653/delete-a-directory 

Scope Version: 8.8 and greater.
Solution

1) Perform database backup.


2) Modify the new LDAP directory model and change the name to the old directory name.


3) Select OK (This re-writes the name attribute to all of the user records and can take a few minutes).


4) Change the LDAP directory name back to the new name and select OK.