Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Eric_Baldwin
New Contributor

IPSec VPN with Active Directory Authentication

I have created a VPN tunnel with the Windows Dialup Template and used a group within the VPN setup to look to for authentication. I created a local firewall test user and placed in group to find that all works successfully. I am able to ping my local servers while connecting through a Verizon hotspot or remote network.

 

I created a user from active directory by going to firewall users and selecting LDAP user. After placing this user into the VPN group i am not able to authenticate. I've made sure my DC DNS servers are specified and tried different security options on the windows 7 side. Example PAP, CHAP, CHAP v2.

 

Any suggestions?

 

I have a FortiGate 100D on 5.4.3 build 1111

5 REPLIES 5
brycemd
Contributor II

Ensure you are using the correct username. By default for the LDAP server, IIRC, it is by 'cn' not 'sAMAccountName'. Which means the username would be the full name. Either try the full name or change the LDAP server Common Name Identifier from cn to sAMAccountName

Heyro
New Contributor

In our company we use firstname.lastname as credentials. When using "CN" in the Common Name Identifier field, the users authenticate with firstname lastname. Instead of the "." they have to use a space. Changing this to "sAMAccountName" in the Common Name Identifier field solved the problem.

Eric_Baldwin

This worked. Thanks a lot. Also the protocol on the windows client side had to be set to L2TP under "Type of VPN" and PAP had to be selected at the bottom.

gsarica

I'm surprised the default isn't 'sAMAccountName', took us a while to figure out why it wasn't working also when we first installed our Fortigate. Is there a use case where someone would use 'firstname lastname' rather than their Windows login ID for just the firewall/VPN?

CodeTron
New Contributor III

Make sure that you have the followings in your LDAP connection string:

Common name identifier : sAMAccountName

and the user name should be in this format:

CN=administrator,CN=Users,DC=domain,DC=com

 

Note: replace domain with your domain name

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors