Setting up a Remote Admin (and/or LDAP) on a firewall on a different subnet from the AD...
(Noobie Alert !! - forgive any non-standard terminology...)
We have 10 FortiGate or FortiWiFi installations across the country, 9 of which are hooked into the 'main' network thru IPSec tunnels. We also have a Primary AD server, and two clone AD's at 3 of the ten locations.
On the locations that have an AD server directly attached (on the same subnet) to a Firewall, I have setup an LDAP, and Remote Users as an ADMINs... On the firewalls without AD servers directly attached, I cannot setup an LDAP poiinting to our primary AD server, which is on a different subnet, and so cannot setup Remote Users...
Everytime our policy dictates that it's time to change a password, for the ADMINs, it needs to be changed in the AD, and on each of the 7 firewalls without an AD server. Needless to say, this leads to much complaining, and occasionally to a screwup where someone needs to signon to the Master Admin to reset another Admin's password...
How do I go about allowing an LDAP entry for an AD on a different subnet (but in the same network)?
Thanks
Jamie
