With Forti Client 7.2.x the connection to LDAP Samba stopped working. From the conversations I have with Fortinet within tickets it seems that they do not intend to fix it. They always refer me to the NFR department. Do you have any solution for this problem? Do we have to slowly prepare to replace FortiClient with some other system?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello I came across thsi reddit post : https://www.reddit.com/r/sysadmin/comments/16d6p1q/forticlient_ems_not_working_with_samba_ad_dc/
I know this thread. But it ended without solving the problem.
So I have another side question. Does anyone still use Samba as AD?
Honestly, it has been a long time I have not seen anyone use it.
There is still no-one who managed to solve this ?
Nicolas
Unfortunately I was not able to solve this. I did tests using WireShark and noticed that ldap drops the connection as soon as FortiClient 7.2.x sends the packet "NTLM Message Type: NTLMSSP_NEGOTIATE (1)" version 7.0.x logged in sending "NTLM Message Type: sasl (3)"
Fortinet technical support has given me to understand that they will not do this.
I also led discussions on Samba mailing but without result.
[2024/11/05 14:19:11.123630, 3] source4/samba/ service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'ldapsrv_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_RESET'
[2024/11/05 14:19:11.124440, 3] source4/samba/ service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'LDAP_PROTOCOL_ERROR'
When Ems 7.2.x logs in it observes in the Samba logs:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.