Hello All,
I hope you're doing well.
I have this error ([1186] fnbamd_ldap_parse_response-Error 1(000004DC: LdapErr: DSID-0C090D93, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v4563)) on ldap debug when i try to access one of my sites through IPSec VPN from FortiClient.
I use an AD account for authentication.
For the bind type, It's Regular.
please what is the issue ?
have a look at https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-troubleshoot-the-Invalid-LDAP-serve...
Thank you for your feedback.
Let me try and get back to you.
if you have a IPsec VPN between sites make sure that you have set the source ip ( not mandatory if i recall correctly ) and there are firewall rules on the remote FGT where the LDAP resides where you have granted access to LDAP from the source ip of the remote FGT.
Yes @funkylicious,
----> the source server IP has been specified in the LDAP configuration.
----> The server IP source has been Added to the local address of phase 2 VPN IPSec site-to-site.
----> That IP has been authorised to communicate with the LDAP server on the FGT remote site.
I have no IP & port communication issue on both Fortigates, just that error I discovered in LDAP debug.
As suggested in the recommendation you shared, we will open a case at Microsoft support .
As a workaround, I have switched to STARTTLS protocol + CA certificate on LDAP server and the authentication is working well.
| User | Count |
|---|---|
| 2839 | |
| 1436 | |
| 812 | |
| 796 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.