Skip to main content
gzarini
New Member
September 2, 2015
Question

Ldap authentication for vpn users.

  • September 2, 2015
  • 1 reply
  • 3350 views

Hi. i'm having issues to authenticate vpn users throught a remote ldap server.

i have created the addresses, portal, policys and everything works fine with local users.

But if i add a remote group to authenticate i can't grant access.

What i did:

Under users authentication,ldap i have created a ldap server, test were successful.

Under users, group, i have created a new group for vpn with remote server. i was able to browse ldap tree and add vpn users group.

The i added that group into the ssl vpn portal, and edit the policy to allow access for users in this group.

 

When i try to connect i got access denied.

 

I did the same steps on other unit and everything worked fine.

 

Software Version 5.2.3 patch 670 on both units.

 

PD: i think i have a problem with ldap because when i try to configure sso in polling mode, i'm able to browse ldap tree, but when i select a group, and i try to apply those changes i got an error of object not found.

 

Thanks.

 

    1 reply

    gzarini
    gzariniAuthor
    New Member
    September 9, 2015

    I solved it.

    The prioblem was that fortigate was sending the cn to the domain controller and i was trying to authenticate using the samaccountname.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!