Forticlient and LDAPS
Hi,
Until now, my LDAP servers were configured for working on port 389.
My User group linked to my LDAP Servers is configured to Any.
The problem is when a password expired for a domain user, my user is blocked because he cannot update it by Forticlient. So, I seted-up LDAPS thanks to this procedure https://www.infosecmonkey.com/2019/04/20/secure-ldap-and-ad-password-change-via-forticlient/
I created a new LDAP server configured to port 636 and linked to my domain cert exported from my AD My user group is linked to this new LDAPS server and configure to a specific AD OU I created a user test who is member of this OU.
The user must change his password at next logon.
But, with this user I have the following error during vpn connection "Credential or SSLVPN configuration is wrong (-7200)"
If I disable the option to change password at next logon, I can connect.
Is it because 2 "rules" are applied to my VPN configuration under "Authentication/Portal Mapping" ?
The original one using LDAP applying to Any and the second one using LDAPS applying to specific OU ? As my user test is member of the OU and also Any, I don't know which "rule" is applied. Let me know if I'm clear or not. Regards,
