Created on
08-11-2025
03:22 AM
Edited on
08-12-2025
02:57 AM
By
Anthony_E
Description | This article describes how to stop automatic connection attempts originating from the FortiGate toward the LDAP server. |
Scope | FortiGate, FortiProxy. |
Solution |
By default, FortiGate automatically starts connecting to the LDAP server once the LDAP server is configured on FortiGate or FortiProxy till the LDAP connection is successful. This behavior can be changed by the 'obtain-user-info' setting in ldap config.
The option 'obtain-user-info' is enabled by default. When 'obtain-user-info' is disabled, FortiGate or FortiProxy will connect to the LDAP server only in the following conditions:
FGT # config user ldap FGT (ldap.server) # end
Packet capture can be taken to verify if LDAP traffic is leaving FortiGate or not:
diagnose sniff packet any 'host x.x.x.x and port 389' 6 0 l <----- Where x.x.x.x is the LDAP server IP.
Packet capture can also be taken directly from the GUI under Network -> Diagnostics.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.