Skip to main content
noother10
New Member
October 8, 2018
Solved

5.4.1 - Unable to LDAP filter for memberOf a group

  • October 8, 2018
  • 4 replies
  • 16061 views

I believe this was an issue with older versions of FortiOS previously. When going to Authentication -> User Management -> User Groups, I hit create and target my remote LDAP (Windows AD), and try to specify the LDAP filter. The filter returns nothing when trying to use the memberOf property to grab members of a specific AD group. When using the information from the Administration Guide to create the filter as per the example, it also fails. I can add the group directly (Windows AD group under User Group), but it won't recognize the users within the group when I try to use FortiToken.

 

If I go to Authentication -> Remote Auth. Servers -> LDAP -> My Win AD Setup -> Remote LDAP Users -> Import users by group memberships, this will work.

 

Is there a way around this, or to make it work? The best I've come up with is to import the users by group memberships, and then in User Groups select the "Set a list of imported remote LDAP users". But this is a manual process with two steps, whereas I was hoping to have it just work off a group, so in future if I want to add someone, I just add them to the Windows AD group.

    Best answer by ergotherego

    I personally like to use Remote User Sync rules. I create one for each remote<>local group mapping.

     

    Some advantages of doing it that way:

     

    1) Auto assignment of mobile token

    2) When you look under your local groups, you can actually see the members. This is helpful for troubleshooting. If instead you define a filter under a group, you can't see who FAC has inside that group.

    3) You can also have the FAC delete old user accounts when they are no longer present on the domain.

    4 replies

    ergotherego
    New Member
    October 8, 2018

    I personally like to use Remote User Sync rules. I create one for each remote<>local group mapping.

     

    Some advantages of doing it that way:

     

    1) Auto assignment of mobile token

    2) When you look under your local groups, you can actually see the members. This is helpful for troubleshooting. If instead you define a filter under a group, you can't see who FAC has inside that group.

    3) You can also have the FAC delete old user accounts when they are no longer present on the domain.

    RobertReynolds
    New Member
    October 8, 2018

    Ive got the memberof LDAP filter working in my 5.4.1 FAC for User Groups using the following for example

     

    (memberof=CN=SSL_VPN_Users,CN=Users,DC=mydomain,DC=co,DC=uk)

     

    where SSL_VPN_Users is a Security Group in the Users OU on mydomain.co.uk

     

     

     

     

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!