Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
huud
New Contributor III

Changing AD Server Integrated with Fortigate VPN ?

Hi,

 

We have a Windows Server 2019 Datacenter Edition AD Server integrated with Fortigate for VPN users, and we are planning to change the version of the AD Server to Standard Edition.

 

Everything will be the same as the original except the version.

 

My question if the LDAP integration will remain intact or will it need to be reconfigured in Fortigate again, and what about the users, will they have to be imported again from the LDAP ?

 

Thank You

1 Solution
ozkanaltas
Valued Contributor II

Hello @huud ,

 

Probably you don't need to make any changes on the FortiGate side. Because FortiGate isn't interested in the Windows server version. Fortigate just cares about the AD tree and credential information. If you do not make any changes to that information(AD tree, CN, DN, User information fields, etc.), you don't need to change anything on the FortiGate side. 

 

If you use LDAPS instead of LDAP, you need to install the new AD certificate to FortiGate. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
4 REPLIES 4
ozkanaltas
Valued Contributor II

Hello @huud ,

 

Probably you don't need to make any changes on the FortiGate side. Because FortiGate isn't interested in the Windows server version. Fortigate just cares about the AD tree and credential information. If you do not make any changes to that information(AD tree, CN, DN, User information fields, etc.), you don't need to change anything on the FortiGate side. 

 

If you use LDAPS instead of LDAP, you need to install the new AD certificate to FortiGate. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
huud
New Contributor III

Thank You,

 

The question was in relation to the Certificates and/or UUID being involved between the AD Server and Fortigate. As its known certificates and UUID are unique, just trying to understand if this might impact the connectivity.

ozkanaltas
Valued Contributor II

Hello @huud ,

 

If you use LDAP instead of LDAPS you do not need to change the certificate. Frankly, I'm not sure about UUID. I think FortiGate uses CN to pull users and groups.

 

Also, I think you can try that before changing the server. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
huud
New Contributor III

Thanks @ozkanaltas 

 

The fortigate has LDAPS configured, and I tested this in a lab environment and manage to change the AD server without changing anything on the Fortigate side, without issues..

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors