Hi
Having an issue with IPSEC users. They can complete LDAP authentication against local DC and because they are using Forticlient, they receive notification when their password has expired. However, our Security posture states that all perimeter authentication must be done against a read-only DC so when the user sees that their passwd has expired, they attempt to reset it and it fails.
Our Netscalars are clever enough to realise they are talking to RODC and accept the referral to talk to RWDC when they need to. Is there anyway that the Fortigate can recognise and follow an LDAP referral which they receive from the RO DC?
Thanks
Conan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1767 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.