FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
Somashekara_Hanumant
Staff & Editor
Staff & Editor
Article Id 371293
Description This article describes how to configure secondary LDAP and troubleshoot.
Scope FortiAuthenticator.
Solution

The user should have 2 LDAP servers with the same domain name, in this case, below are the LDAP servers:

  • Domain Name: dxb-nse8.lab
  • Primary: 10.108.3.15 (hostname - NSE8-DC).
  • Secondary: 10.108.3.122 (hostname - NSE8-DC1).

 

On FortiAuthenticator configure the LDAP configuration below:

 

Secondary_server.png

 

The user can try to press the 'Browse' option to verify whether the LDAP server is working or not.

 

LDAP_browse.png

 

To verify whether the secondary LDAP 10.108.3.122 is working or not, the user has to disable the NIC on the primary server or make sure the primary LDAP is not reachable from FortiAuthenticator (by changing the IP address)

 

Then start the packet capture on the respective interface on FortiAuthenticator, then browse the LDAP as above, now the traffic should reach the secondary server.

 

Refer to the below sniffer traces:

 

snifer.png