FortiGate-81F # diagnose debug fsso-polling detail
AD Server Status(err: server can not be accessible):
ID=1, name(172.18.0.1),ip=172.18.0.1, port=0, source(security), users(IPv4:0, IPv6:0),
username=swd\lcloperator2
read log eof=0, latest logon timestamp: Thu Jan 1 03:00:00 1970
polling frequency: every 10 second(s), success(0), fail(106)
LDAP status: init
LDAP query: success(0), fail(0)
LDAP max group query period(seconds): 0
this is branch location firewall the AD is in DC location
also i checked the Fortinet documents but still i didn't find any solution
can you please help me on this
Note: Agentless polling mode
Solved! Go to Solution.
Hi,
Please refer below article and follow the tshoot steps:-
You may share the sniff.
Check communication between FortiGate and the DC on TCP port 445.
diagnose sniffer packet any "host <DC IP> and port 445" 4 0 a
Also how branch FGT is communicating with the DC FGT via IPSEC TNL?
Do you confirm in LDAP server config the "Test User Credentials" works successfully ?
Tested Successfully
Can you check if 172.18.0.1 allows FGT to connect to port 445 TCP?
You can try a telnet test from FGT to DC:445.
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.