FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
slovepreet
Staff
Staff
Article Id 252955
Description

This article describes how to troubleshoot the 'Invalid LDAP server' Error.

Scope FortiGate.
Solution

Sometimes, the LDAP server is connected successfully and is able to authenticate the username as well against the LDAP server.

When the group information is trying to be pulled, it will give the error 'Invalid LDAP server'.

It will keep loading as shown in the picture.

 
error.jpg.png
 
  • Finally, it will give the error 'Invalid LDAP server'.
  • If a Wireshark capture is run, 'abandon request' information will appear:

 

Picture1.png

  • This abandon request happens when the FortiGate sends the request to the LDAP server and if after a certain time, it does not receive the response from the server it will send this request to stop this operation.
  • There could be multiple reasons for that, but one reason is that there might be some latency in the customer environment and that’s why this operation does not get completed.
 

Solution:

 

  • To resolve this issue, it is possible to increase the value of remote authentication timeout:

 # config system global

     set remoteauthtimeout 300 <-----  Default value is set to 5

 end

 

For further LDAP troubleshooting refer to this article below:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Fortigate-LDAP/ta-p/196280

 

  • It is also possible to try using the BIND type on the LDAP server as Regular and put the credentials.
  • After that, it is possible to go back and check again if it still shows the same error.

 

If the issue persists, contact Fortinet Support.