Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SFW
New Contributor

Active Directory Connector cannot connect but the LDAP is connected is successfully

FortiGate-81F # diagnose debug fsso-polling detail
AD Server Status(err: server can not be accessible):
ID=1, name(172.18.0.1),ip=172.18.0.1, port=0, source(security), users(IPv4:0, IPv6:0),
username=swd\lcloperator2
read log eof=0, latest logon timestamp: Thu Jan 1 03:00:00 1970

polling frequency: every 10 second(s), success(0), fail(106)
LDAP status: init

LDAP query: success(0), fail(0)
LDAP max group query period(seconds): 0


this is branch location firewall the AD is in DC location 
also i checked the Fortinet documents but still i didn't find any solution 
can you please help me on this 

Note: Agentless polling mode

1 Solution
sjoshi
Staff
Staff

Hi,

 

Please refer below article and follow the tshoot steps:-

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-FSSO-agentless-p...

 

You may share the sniff.

Check communication between FortiGate and the DC on TCP port 445.

 

diagnose sniffer packet any "host <DC IP> and port 445" 4 0 a

 

Also how branch FGT is communicating with the DC FGT via IPSEC TNL? 

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi

View solution in original post

12 REPLIES 12
AEK
SuperUser
SuperUser

Do you confirm in LDAP server config the "Test User Credentials" works successfully ?

AEK
AEK
SFW
New Contributor

Screenshot 2025-07-21 162207.png

Tested Successfully

AEK
SuperUser
SuperUser

Can you check if 172.18.0.1 allows FGT to connect to port 445 TCP?

You can try a telnet test from FGT to DC:445. 

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors