Hi every one,
I config LDAP as link: https://blogs.msdn.microsoft.com/microsoftrservertigerteam/2017/04/10/step-by-step-guide-to-setup-ld...
Do not use SSL , LDAP joined domain,
dsquery user -name ldap
CN=LDAP,OU=Users,OU=SYSTEM,OU=VIFB,DC=vifb,DC=local
Hi,
I'd try CLI ..
1. enable debug
diag debug reset
diag debug app fnbamd 7
diag debug enable
2. then test
diag test auth ldap <SERVER> <username> <password>
.. and fnbamd should let you know if first regular bind failed or haven't found user or so.
I gues sit's failing on first bind, so account used for regular bind has no sufficient rights, or correct password, or FGT has no access to LDAP (some firewall on the way).
Alternatively .. diag sniff packet any 'host <LDAP-IP> and port <LDAP PORT 389>' 6 0 a or sniff LDAP traffic from gui to see directly in packets what LDAP server said, if anything.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi,
Tks xsilver .
A major benefit of Polling mode is that no FSSO DC Agents are required . So I config LDAP on windown server . provider said LDAP is fault .
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.