Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Vik1
Visitor

LDAP Configuration issue with IPSec tunnel

Dear All,

 

We have created an IPSec tunnel between our HO and local location. The LDAP servers are hosted on HO Location and are we login the firewall based on AD user ID. But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID.

 

We have checked the configuration and the routes and also we have tried adding the tunnel to our SDWAN rules as per the requirement but we are facing the same issue. Today, one of our ISP was down and the entire traffic was switched to the secondary tunnel and we could not access the firewall as well as FortiManager. Post the ISP was up, we had to bring the secondary tunnel down and then we were able to access both devices.

 

Please align someone on this call as soon as possible.

Mayank Dadheech
Mayank Dadheech
1 REPLY 1
johnathan
Staff
Staff

"But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID."

Just wanna confirm, you can ping  and access the firewall over the secondary tunnel while the issue is occurring, you just cannot login?
You may need to set a specific source IP for the LDAP server in order for the FortiGate to reach it over the tunnel. See this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-set-source-IP-address-for-FSSO-LDAP...

"Never trust a computer you can't throw out a window."
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors