Hello,
I have VPN site to site to connecting on-prem to the azure. The connection was working properly, local subnet in the on-prem can communicate to the remote subnet on azure.
But if i execute ping from FortiGate management ip why is not reachable? So if i change my LDAP connection from Server located in the on-prem to Azure VM, the connection is not success.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @HS08 ,
You can try to configure an IP address in tunnel interface then specify a source-ip. Check the KB below.
HI I'm not found where i should specify source-ip on my VPN site to site tunnel. Are you know where?
Hi @HS08 ,
You need to configure tunnel IP address under Network > Interface > then locate the IPsec tunnel interface. After that, follow the guide given previously and see if it will work.
HI..
I'm not talking about SSL VPN but Site to Site VPN. What we see in interface is interface for SSL VPN.
Hi @HS08 ,
You should be able to see the IPsec tunnel interface once you dig deeper under the WAN interface or whatever interface you have configured for IPsec VPN. This is different to the 'ssl.root' interface which is used for SSL-VPN.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IP-address-on-an-IPSec-tunnel-in...
Regards,
Under LDAP can you specify the source IP as your on-prem interface IP and check?
# config user ldap
edit <LDAP object name>
set source-ip <IP address associated an interface>
end
make sure you are able to ping LDAP server on Azure is pingable using the source Ip (on-prem interface IP )
Hi @HS08,
It depends whether your management IP is included in the phase2 selectors or not and whether it is allowed in the firewall policy or not. For LDAP over IPsec tunnel, please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Authentication-with-remote-LDAP-via-site-t...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.