Skip to main content
siebr001
New Member
January 27, 2025
Solved

Problem with FortiGate RBAC authentication against AD

  • January 27, 2025
  • 1 reply
  • 447 views

Hi,

 

I am trying to configure LDAP for user authentication against AD. This works fine for users that are directly member of the group that is mentioned in the User Group configuration.

 

The design, however, is that a user is member of a Role and the Role is member of the group. When I have this configured in AD it does not work anymore. When I make the user a direct member of the group again it works.

 

How to get this working?

 

Regards, Wim

Best answer by siebr001

Hi,

 

I already found the answer: add the option "set search-type recursive" to the ldap configuration on the command-line.

 

https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/107067/enabling-active-directory-recursive-search

1 reply

siebr001
siebr001AuthorAnswer
New Member
January 27, 2025

Hi,

 

I already found the answer: add the option "set search-type recursive" to the ldap configuration on the command-line.

 

https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/107067/enabling-active-directory-recursive-search