Dear All,
We have created an IPSec tunnel between our HO and local location. The LDAP servers are hosted on HO Location and are we login the firewall based on AD user ID. But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID.
We have checked the configuration and the routes and also we have tried adding the tunnel to our SDWAN rules as per the requirement but we are facing the same issue. Today, one of our ISP was down and the entire traffic was switched to the secondary tunnel and we could not access the firewall as well as FortiManager. Post the ISP was up, we had to bring the secondary tunnel down and then we were able to access both devices.
Please align someone on this call as soon as possible.
Solved! Go to Solution.
"But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID."
Just wanna confirm, you can ping and access the firewall over the secondary tunnel while the issue is occurring, you just cannot login?
You may need to set a specific source IP for the LDAP server in order for the FortiGate to reach it over the tunnel. See this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-set-source-IP-address-for-FSSO-LDAP...
"But as soon as the tunnel is up, we cannot access the firewall as well as FortiManager using that tunnel. We have to bring the tunnel down manually to access the firewalls through the LDAP user ID."
Just wanna confirm, you can ping and access the firewall over the secondary tunnel while the issue is occurring, you just cannot login?
You may need to set a specific source IP for the LDAP server in order for the FortiGate to reach it over the tunnel. See this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-set-source-IP-address-for-FSSO-LDAP...
Thanks Johnathan, post assigning the source IP, the LDAP server was connected and we were able to login in the firewall. But, I still couldn't understand that why post disabling the IPSec tunnel, the issue was getting fixed. May be I am missing out on something. Please guide me for this if you can. Thanks again for your help.
User | Count |
---|---|
1922 | |
1144 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.