FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
GiannisChari
Staff
Staff
Article Id 353771
Description This article describes how to resolve a scenario where FortiGate has an LDAP (Lightweight Directory Access Protocol) object that is used for active directory user authentication, but the client gets the wrong user credentials.
Scope FortiGate.
Solution

While testing an Active Directory user, the following error appears:

 

error.png

 

On a packet capture for port 389 on FortiGate, the LDAP SearchRequest for User1 gets this reply:

 

error2.png

 

There are two possible reasons why error 0x4DC may appear. The first possible reason is a wrong user password. It may also be the case that simple bind is disabled on the active directory. It can be reactivated by adding pwdssp.dll on the SecurityProviders key in the server Registry.

 

pwd.png

 

Note:

The key path is 'HKLM/SYSTEM/ControlSet/Control/SecurityProviders' and, in some cases, 'HKLM/SYSTEM/ControlSet001/Control/SecurityProviders' and 'HKLM/SYSTEM/ControlSet002/Control/SecurityProviders' need to be changed instead.