Description | This article describes how to configure a Global Catalog server port in LDAP configurations for FortiGate, FortiProxy, and FortiAuthenticator. |
Scope | FortiGate, FortiProxy, and FortiAuthenticator. |
Solution |
In order to create a single LDAP entry for the root domain and to take advantage of the benefit of Global Catalog to query and search objects from other child domains in the same Active Directory Forest, it is possible to configure Fortinet products to use Global Catalog port 3268 or 3269 (Secure) to communicate with domain controllers.
The Global Catalog server primarily provides a distributed directory service that contains a partial replica of all domain directory partitions in the forest. It is used to support forest-wide searches and queries.
In this example, a Root domain and a child domain have been created in a single forest. Root Domain: Root.Local Child Domain: Child.Root.Local
Root Domain Controller Name: DC01.root.local
Note: Ensure DNS is configured properly, as authentication is highly dependent on name resolution.
Root Domain:
Child Domain:
Logon to FortiAuthenticator and expand Authentication -> Remote Auth. Servers -> LDAP.
Alternatively, select users:
Select OK to import users.
CLI configuration:
Despite having configured DN 'dc=root,dc=local,' it is still possible to authenticate users through the child domain 'child.root.local.'
LDAP users and groups can now be created in FortiGate from Child domains and used with multiple policies.
In FortiGate, it is possible to do the same with LDAP groups:
Note:It is also possible to configure FortiGate, FortiAuthenticator, FortiProxy, and other Fortinet products to use Secure Global Catalog LDAPS port 3269 if the PKI infrastructure is already in place and the required certificates are installed and trusted by the Fortinet Products. It is possible to use an Internal CA or public CA for the LDAPS (3269) port
For details about how a Global Catalog server works, see the Microsoft documentation.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.