Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Vik1
New Contributor

LDAP Configuration issue with IPSec tunnel

Dear All,

 

We have created an IPSec tunnel between our HO and local location. The LDAP servers are hosted on HO Location and are we login the firewall based on AD user ID. But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID.

 

We have checked the configuration and the routes and also we have tried adding the tunnel to our SDWAN rules as per the requirement but we are facing the same issue. Today, one of our ISP was down and the entire traffic was switched to the secondary tunnel and we could not access the firewall as well as FortiManager. Post the ISP was up, we had to bring the secondary tunnel down and then we were able to access both devices.

 

Please align someone on this call as soon as possible.

Mayank Dadheech
Mayank Dadheech
1 Solution
johnathan
Staff
Staff

"But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID."

Just wanna confirm, you can ping  and access the firewall over the secondary tunnel while the issue is occurring, you just cannot login?
You may need to set a specific source IP for the LDAP server in order for the FortiGate to reach it over the tunnel. See this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-set-source-IP-address-for-FSSO-LDAP...

"Never trust a computer you can't throw out a window."

View solution in original post

2 REPLIES 2
johnathan
Staff
Staff

"But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID."

Just wanna confirm, you can ping  and access the firewall over the secondary tunnel while the issue is occurring, you just cannot login?
You may need to set a specific source IP for the LDAP server in order for the FortiGate to reach it over the tunnel. See this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-set-source-IP-address-for-FSSO-LDAP...

"Never trust a computer you can't throw out a window."
Vik1
New Contributor

Thanks Johnathan, post assigning the source IP, the LDAP server was connected and we were able to login in the firewall. But, I still couldn't understand that why post disabling the IPSec tunnel, the issue was getting fixed. May be I am missing out on something. Please guide me for this if you can. Thanks again for your help.

Mayank Dadheech
Mayank Dadheech
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors