Skip to main content
spanz
Visitor III
November 24, 2021
Solved

Can't contact LDAP server

  • November 24, 2021
  • 5 replies
  • 13558 views

Hi,

I'm managing 30 branches, all connected via MPLS and running FGTs as firewalls.

There's a main site with a DC (10.7.7.80).

I wanted to authenticate fortigate administrators via LDAPS and use their AD accounts for login.

However, it is working in some of the sites, and not working on the rest.

 

If i check the logs on the main site, I can see the packet is accepted

spanz_0-1637742221511.png

but I can also see this session timeout if I click on this line of log:

spanz_1-1637742288015.png

Some of the FGTs are able to contact the DC, when I look on their logs, it looks the same just without this "session timeout".

 

I tried to increase the ldap query timeout on appliances which have this problem:

 set remoteauthtimeout 15

 set ldapconntimeout 8000

 

but still the same.

 

Will appreciate any help and advices.

 

Thanks!

 

 

Best answer by spanz

You right sir.

I already fixed it, I thought I have locked this post.

 

Thanks you

5 replies

Shivasagar
Staff
Staff
November 25, 2021

Hi, You can try the debugging mentioned in the below KB for additional details when the login fails.

https://community.fortinet.com/t5/FortiGate/Technical-tip-How-to-create-administrators-which-can-be/ta-p/190870?externalID=FD32608

 

# diag debug enable
# diag debug application fnbamd -1

// Try login which fails//

# diag debug disable

ConnyGustavsson
Visitor III
November 26, 2021

Hi. Could it be so that not all the "WAN link" subnets in MPLS are "known"/distributed in routing? Test to ping the AD server from a failing firewall. If problem, try to add a "source-ip" in CLI for the LDAP config using one of the LAN interface IPs. /Conny

The_Physicist
Visitor III
November 26, 2021

source-ip works in many cases.

gixxerlegend
New Member
October 18, 2024

adding source-ip to the ldap config fixed it for me too.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.