Description |
This article describes how to fix the connection error 'Stronger (er) authentication required' that occurs when trying to integrate Windows Server 2025 LDAP with FortiGate. |
Scope | FortiGate, Windows Server 2025. |
Solution |
When integrating an LDAP service with FortiGate with Windows Server 2025, the error 'Stronger (er) authentication required' may appear.
This is due to additional security settings on the group policy applied to the domain account used.
The additional security option is the LDAP server signing requirements Enforcement. The default value on Windows 2025 server is set to 'Not Defined' and will not allow the connection.
The setting must be set to the following value, depending on customer requirements:
If LDAP is configured via port 389, update the settings as follows:
If LDAP (Over SSL connection) is configured via port 636, the Domain controller: LDAP server signing requirements Enforcement value must be changed to 'Enabled'.
Related articles: Troubleshooting Tip: FortiGate LDAP troubleshooting and debug logs created by fnbamd |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.