Created on
07-13-2015
06:05 AM
Edited on
09-11-2025
05:49 AM
By
Jean-Philippe_P
Description
Scope
FortiGate.
FortiAuthenticator.
Solution
Go to Network -> Interfaces -> Access Rights -> Services, select the check box for LDAP (TCP/389).
Go to Authentication -> User Management -> User Groups -> Create New, create a new group named: ‘ldap_admins’.
Go to Authentication -> User Management -> User Groups -> Create New, create a new group named: ‘testgrp’.
Go to Authentication -> User Management -> Local Users -> Create New.
ldapadmin -> to the group ldap_admins.
Add rights to the 'ldapadmin' user for LDAP browsing.
test1 -> To the group testgrp.
After configurations are done:
Go to Authentication -> LDAP Service -> Directory Tree.
FortiGate Configuration.
Complete using:
Verify the fnbamd debugs by running the following commands in FortiGate:
diagnose debug console timestamp enable
diagnose debug application fnbamd -1
diagnose debug enable
Debug output example:
2025-09-11 13:40:08 [1982] ldap_copy_grp_list-copied cn=ldap_admins,dc=example,dc=com
2025-09-11 13:40:08 [195] find_matched_usr_grps-Skipped group matching
2025-09-11 13:40:08 [2553] fnbamd_ldap_result-Result for ldap svr LDAP is SUCCESS
2025-09-11 13:40:08 [2564] fnbamd_ldap_result-Skipping group matching
2025-09-11 13:40:08 [909] update_auth_token_session-config does not require 2fa
2025-09-11 13:40:08 [239] fnbamd_comm_send_result-Sending result 0 (nid 0) for req 120598576119810, len=2629 <- 0 means an authentication success; 1 means a failed authentication.
2025-09-11 13:40:08 [600] destroy_auth_session-delete session 120598576119810
To get detailed LDAP logs in FortiAuthenticator, navigate to https://<Fortiauthenticator_ip or fqdn>/debug and then select Other -> LDAP.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.