We upgraded our Fortigate 200D to firmware v6.0.0 on Tuesday and since then, some users have been unable to connect to the VPN.
In my testing I've found what I think is the cause but haven't been able to fix it. After the upgrade, when some users authenticate to the LDAP server(s) the password check succeeds but no AD group membership information is returned.
For example:
diag test authserver ldap LDAPSERVER username1 password1
gives us:
authenticate 'username1' against 'LDAPSERVER' succeeded!
Group membership(s) - CN=group1,OU=blahblah,DC=contoso,DC=com
CN=group2,OU=blahblah,DC=contoso,DC=com
etc.
however
diag test authserver ldap LDAPSERVER username2 password2
gives us:
authenticate 'username2' against 'LDAPSERVER' succeeded!
The second user's groups are not displayed, and the second user is given an invalid permissions error when trying to log in to the VPN. These users can be in the same groups and in the OU in Active Directory - it appears to be random for who is affected.
I will be downgrading back to 5.6.4 if I can't figure this out, but I'd rather get it resolved.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
6.0.1 release notes has this in resolved issues.
483553 In case there are multiple LDAP search results for the same LDAP search query, LDAP group match fails. But I would just go back whatever working before.6.0.1 release notes has this in resolved issues.
483553 In case there are multiple LDAP search results for the same LDAP search query, LDAP group match fails. But I would just go back whatever working before.Interesting. I guess I'll downgrade for now and wait for 6.0.1 to become available.
Thank you!
It's available now. Otherwise, we can't download the release notes.
That's even better. I see it's available for manual download/installation, it just wasn't showing up on the Fortigate itself as an available upgrade. I'll try 6.0.1 tonight, thank you again.
6.0.1 resolved the issue.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.