Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tomeks
New Contributor II

Forti Client EMS + LDAP SAMBA

With Forti Client 7.2.x the connection to LDAP Samba stopped working. From the conversations I have with Fortinet within tickets it seems that they do not intend to fix it. They always refer me to the NFR department. Do you have any solution for this problem? Do we have to slowly prepare to replace FortiClient with some other system?

6 REPLIES 6
spoojary
Staff
Staff

Hello I came across thsi reddit post : https://www.reddit.com/r/sysadmin/comments/16d6p1q/forticlient_ems_not_working_with_samba_ad_dc/

 

 

Siddhanth Poojary
tomeks
New Contributor II

I know this thread. But it ended without solving the problem.

tomeks
New Contributor II

So I have another side question. Does anyone still use Samba as AD?

spoojary

Honestly, it has been a long time I have not seen anyone use it.

Siddhanth Poojary
informatiquejoskin
New Contributor

There is still no-one who managed to solve this ?

 

Nicolas

tomeks
New Contributor II

Unfortunately I was not able to solve this. I did tests using WireShark and noticed that ldap drops the connection as soon as FortiClient 7.2.x sends the packet "NTLM Message Type: NTLMSSP_NEGOTIATE (1)" version 7.0.x logged in sending "NTLM Message Type: sasl (3)"

Fortinet technical support has given me to understand that they will not do this.

 

I also led discussions on Samba mailing but without result.


[2024/11/05 14:19:11.123630, 3] source4/samba/ service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'ldapsrv_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_RESET'
[2024/11/05 14:19:11.124440, 3] source4/samba/ service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'LDAP_PROTOCOL_ERROR'


When Ems 7.2.x logs in it observes in the Samba logs:

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors