Skip to main content
alaurent
New Member
September 4, 2017
Solved

Unable to add a LDAP Server (FOS 5.6 to Windows Server 2003)

  • September 4, 2017
  • 8 replies
  • 33545 views
I can not configure an LDAP Server on an FG-60E with FortiOS 5.6   I am trying to set up an FSSO from an FG-60E and a Windows Server 2003, but I can not add the LDAP server.   After placing the IP of the Windows 2003 Server, as well as the user and password of the domain administrator, when doing Browser to identify the Distinguished Name, the system indicates: "Invalid LDAP server"   If I put the Distinguished Name manually, and try to test the connection, it says "Invalid credentials"   All this despite the IP of the server is correct, as well as the user and password, which I am placing flat: User = Administrator Key = #####   Waiting for your comments
    Best answer by alaurent

    Hello

     

    The domain\username solve the problem.

     

    Final conf:

    Name: Local_LDAP Server IP/Name 192.168.1.29 Server Port: 389 Common Name Identifier: sAMAccountName Distinguished Name: DC=comapny1,DC=company,DC=com Bind Type: Regular Username: domain\username Password: â€¢â€¢â€¢â€¢â€¢â€¢â€¢â€¢

     

    Thanks

     

     

     

    8 replies

    Allan_Lago
    New Member
    September 4, 2017

    Hi alaurent,

     

    If you use Distinguished Name as your Common Name Identifier you have to change your user to DN Format which is something like this: CN=User Name, OU=Users, DC=contoso, DC=com

     

    If you want to use the user account name your have to change the common name identifier to sAMAccountName.

     

    Hope it helps.

     

     

     

     

     

    alaurent
    alaurentAuthor
    New Member
    September 4, 2017

    The Windows Server and the FG are in the same network, so there are no comunication limitations

     

    My FG configurations is:

    Name: Local_LDAP Server IP/Name 192.168.1.29 Server Port: 389 Common Name Identifier: cn Distinguished Name: DC=comapny1,DC=company,DC=com

    Bind Type: Regular

    Username: Administrator Password: â€¢â€¢â€¢â€¢â€¢â€¢â€¢â€¢

     

    From de Windows Server

    C:\Documents and Settings\>dsquery user "CN=Administrator,CN=Users,DC=company1,DC=company,DC=com"

    Allan_Lago
    New Member
    September 4, 2017
    Did You tried change the Common name identifier as i suggested? Change It from CN to sAMAccountName and you'll be just fine.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!