Created on
06-29-2025
10:15 PM
Edited on
06-30-2025
09:36 PM
By
Anthony_E
Description | This article describes the behavior related to the LDAP authentication failure using the FortiToken as MFA, even if the user and password are correct. |
Scope |
FortiGate up to v7.6.2, SSL VPN web access, FortiToken, LDAP user added on the FortiGate (Not FSSO). |
Solution |
After running the following CLI command:
When it works as expected, there is a line:
When the issue happens and there is a line:
But the credentials are unquestionable, it is required to check the account on the Active Directory, because the FortiGate does not handle the account management, like password expiration. A recommendation is to reset the password and uncheck the option for the user to change the password on the next logon, if it is the case of a password issue on the account.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.