Created on
12-03-2023
10:36 PM
Edited on
08-03-2025
03:57 PM
By
Stephen_G
Description | This article provides some common troubleshooting scenarios for LDAP Authentication. |
Scope | FortiManager/FortiAnalyzer v6.x and v7.x. |
Solution |
Debug Commands for LDAP Authentication:
diagnose debug application authentication 255 <----- Or 8. diagnose debug enable
Scenario 1: Invalid Password.
Solution:
Scenario 2: User does not exist in FortiManager/FortiAnalyzer.
Solution: Create an Administrator on FortiManager/FortiAnalyzer under System Settings -> Admin -> Administrators.
Scenario 3: The user does not exist on the LDAP Server.
Solution: Verify that the LDAP user is created on the LDAP server.
Scenario 4: Distinguished Name for LDAP Server is incorrectly configured on FortiManager/FortiAnalyzer.
The above debug shows searching for users with the configured Distinguished Name or Common Name Identifier fails.
Solution:
Scenario 5: Invalid Credentials for LDAP Binding Admin.
The above debug shows that the LDAP connection is denied due to incorrect credentials configured for User DN and/or Password for the LDAP Server.
Solutions:
Scenario 6: FortiManager/FortiAnalyzer cannot contact the LDAP Server.
Solution:
Scenario 7: There is no CA cert found via FortiAnalyzer.
The debug output above shows LDAP using port 636, able to reach the LDAP and find the user. However, the CA section is empty.
Solutions:
Related articles: Technical Tip: Configuring LDAPS on FortiManager and FortiAnalyzer Technical Tip: Configuring LDAP system administrators in FortiManager for FortiGate |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.