Fortinet external AD Connector and retrieving of ad-user working / ad-userbased policy not
Hello,
I was able to set up external AD connector and retrieve users from AD-Server. But, as soon as I use a retrieved user in a policy (LAN-WAN) the user is not able to connect to the internet.
The policy itself has as source the name of the ad-user & all. Destination: all, Services ALL.
Debuglog shows:
smbcd: rpc_cmd_eventlog_read:946 init=0, eof=1, timestamp=1715756519, Wed May 15 07:01:59 2024 status=0 smbcd: smbcd_process_request:987 got cmd id: 6 smbcd: smbcd_process_request:1000 got rpc log field. smbcd: smbcd_process_request:1012 got rpc username: fortiadlookup smbcd: smbcd_process_request:1018 got rpc password: XXXXXXXX smbcd: smbcd_process_request:1022 got rpc port: 0 smbcd: smbcd_process_request:1028 got rpc logsrc: security smbcd: smbcd_process_request:1121 got net_addr smbcd: smbcd_process_request:1006 got rpc server: 192.168.10.234 smbcd: smbcd_process_request:1055 got VFID, 0 smbcd: smbcd_process_request:1194 got rpc eventlog read command smbcd: rpccli_eventlog_open:202 /code/daemon/smbcd/smbcd_eventlog.c-202: evenglog handle get failed.nt_status:-1073741790. Retry to open pipe with auth. smbcd: eventlog_read:621 loop=0, timestamp=1715756519, Wed May 15 07:01:59 2024 smbcd: rpc_cmd_eventlog_read:946 init=0, eof=1, timestamp=1715756519, Wed May 15 07:01:59 2024 status=0
All connection tests to the AD are working.
Am I missing something?
Thanks a lot!
EDIT: I think I will go and try the standalone Collector Agent as I read this one here:
Poll Active Directory issue after installed the Wi... - Page 2 - Fortinet Community
and diagnosed things by doing:
How to troubleshoot FSSO agentless pollin... - Fortinet Community
