Skip to main content
kogint
New Member
August 21, 2018
Question

LDAP connection issues

  • August 21, 2018
  • 2 replies
  • 6419 views

Running FortiClient EMS 5.4 w/ LDAP

When connecting the domain, I use the credentials, and am using the DN: OU=Group2,OU=Group1,DC=Controller,DC=com

I run test and the test clears, but it won't populate the domain with the endpoints.

We were using this DN just fine until the endpoints stopped populating during sync.

It populates the domain list with Group1 -> Group2, but no endpoints.

 

Logs show:

[FcmAdDaemon Active Directory Error] Connect LDAP: The LDAP server is unavailable.

Workgroup enumeration is disabled

 

On my endpoint, it's also showing telemetry can't reach the EMS host.

 

Much appreciated. If any additional info is needed, let me know.

    2 replies

    kd007
    New Member
    September 5, 2018

    Is port 389/tcp open from the EMS server to your domain controllers?

    Also, I would suggest only using the DN of your root domain rather than trying to filter it by OU at this step: just DC=Controller,DC=com instead of OU=Group2,OU=Group1,DC=Controller,DC=com.

    Also, for the Bind type, which do you have selected? I always use Regular, with the UPN for the authorized username.

    emnoc
    New Member
    September 5, 2018

    Can you the check based DN and authenrtication,  use curl to test also .

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!