Description | This article describes a possible error that can be seen in the WAD debug when authenticating a user with Kerberos. |
Scope | FortiGate. |
Solution |
This error is seen when the time difference (skew) between the client machine and Service and the Kerberos Key Distribution Center (KDC) is too large for the authentication process to succeed.
A good practice is to use the same NTP server across all the network devices. If not, then adjust the time manually to the same time in the Windows Active Directory, Client Machine, and FortiGate.
The Skew can be adjusted in the Windows Active Directory by following the below path. The default value is 5 minutes and it is not recommended to tweak this setting.
From the Windows terminal, type gpedit.msc -> Navigate to Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Kerberos Policy -> Max tolerance for computer clock synchronization.
Below is the error which can be seen in the logs:
diag wad debug enable category auth
[I][p:518][s:12110505][r:184590895] wad_auth_rule_match :1329 match auth rule succ: kerberos_rule |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.