Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi - I'm running into a similar issue and I'm leaning towards LDAP on our FortiGate. Did you ever resolve the issue in your domain?
Hi jtrin,
could you elaborate on your case a bit more ?
Because what you might missed is that post you commented on is from 2010 and FortiOS 4.2.2. Which is pretty old.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi, we're on 7.2.8, and trying to rule out possibilities of the cause. Random accounts are getting locked out daily, even disabled accounts. Maybe about 5 accounts per day. The above post had similar details to what we're going through now. We have regular LDAP connection with domain auth setup in FortiGate and I can see something is triggering the credential validation. Source ip is the FortiGate, but can't tell if it's a false positive.
Hi jtrin,
You can check on the User Event logs if it is matching the timestamp. You may also find there the source IP that is causing the lockout.
I believe I've resolved the issue this morning. Correct, the source IP is the FortiGate, that's what lead me to LDAP. An MSP used a domain admin account to authenticate LDAP. I created a new domain account and added it to the Account Operator domain group. I changed the login for LDAP in FortiGate to that new domain account. The issue went await. I haven't had a lockout or failed attempt from the source ip since the change and that's unheard of for us. I also updated the distinguished name in LDAP settings and narrowed it down to a specified OU instead of the entire directory like the MSP had it. These MSP firms aren't as good as they portray themselves.
Is there a way we can reduce the frequency FortiGate queries LDAP? Right now, the event logs on the domain controller is showing FortiGate is constantly querying LDAP.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.