LDAP queries not forwarded via IPSec VPN, why?
Might be a simple one for you. Any hint is appreciated.
I have a FGT-60F cluster that has an active LDAP server pointing to an AD server that is located on a local "internal1" interface. This connection works fine. If I do "Test Connectivity", I can see in the packet capture (on internal1) some LDAP bindrequests on port 389. LDAP works perfectly.
I want now to add another LDAP Server that is located behind an IPSec VPN. However, the packet capture on the VPN interface does not show any LDAP traffic at all when I do "Test Connectivity".
Routing is correct. Traffic beween local interface and remote network via VPN tunnel is working fine.
I suspect a policy issue, but I have to admit I am puzzled. Since the fortigate is the originator of the LDAP requests, what do I have to choose for the originating interface in the policy setup?
And why do I not have to setup a policy for the LDAP Server on the internal1 interface?
In any case, how would I, step by step, troubleshoot the issue and how would I make it work?
At the end, the LDAP server behind the VPN tunnel should be reachable.
Am I missing something?
Thanks
Dan
