Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
atravel
New Contributor III

On and off SSLVPN configuration is wrong (-7200) at 48%

We get this message 
"Message Remote LDAP user authentication(chap) with FortiToken failed: invalid password" 

We also get intermittent
"Cannot add user from LDAP server because of this error: Failed to import user "" (rule: AD Sync), The username attribute cannot be retrieved" 

9 REPLIES 9
akanibek
Staff
Staff

 
 
 
 

ForumUpdateFAC.png

 

@atravel, could you tell us if your FAC is added to the Active directory as machine entity? And, if the option 'Use Windows AD Domain Auth' is enabled in the appropriate radius policy? 

 

Below you can find article about these, and doc link.

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Joining-FortiAuthenticator-in-the...

 

https://docs.fortinet.com/document/fortiauthenticator/6.0.3/administration-guide/641286/remote-authe...

 

 

 

Asset
atravel
New Contributor III

Use Windows AD Domain Auth is not enabled. 1sslerror.JPG

akanibek
Staff
Staff

What device is acting as radius Client? Could you adjust on Radius Client auth. method to PAP, and test it? If it works, you can keep working with PAP method, otherwise you should configure options above.

Asset
atravel
New Contributor III

Our FortiGate is radius Client. 

atravel
New Contributor III

Is this ok?2sslerror.JPG

akanibek
Staff
Staff

Could you share the screen from Radius server configuration on Fortigate? 

 

Asset
atravel
New Contributor III

3sslerror.JPG

akanibek

Change please 'Authentication method' to Specify > PAP, and try to reproduce the issue.

 

Asset
atravel
New Contributor III

I made the change and Im monitoring the logs to see if the error will reappear. 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors