Dear all
I have 2 AD, Primary and secondary LDAP server.
I already setup user authentication at Firewall Policy for 4 users. (1 policy for 4 users)
I have only one user cannot sign-in on captive portal If I changed the LDAP setting to Primary this user cannot sign-in on captive portal page.
but If I changed the LDAP to secondary this user can signed-in on captive portal page. 
How can I investigate this issue?
Hi,
you can investigate with this debug command:
Enable debug
diagnose debug application fnbamd -1
diagnose debug enable
Disable debug
Here LDAP it's explained in details:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Fortigate-LDAP/ta-p/196280
In addition to eb, run the debug for both cases
- connecting to primary LDAP server
- connecting to secondary LDAP server
then you can compare. It does sound like the server response from the secondary is different in some way.
Thanks so much Markus
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2645 | |
| 1405 | |
| 810 | |
| 688 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.