Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
akhan2
New Contributor

Remote user sync rule

Hi Everyone , 
I am facing a strange issue with sync rules. I have created sync rule to import the remote LDAP users. Sync is not happening correctly  because it does not reflect the correct users of the remote LDAP group.

I move the user to another OU  which is not part of the filter and the user is not removed from the group. I have also deleted the user for test purposes and user still remains in the remote users.

 

1 Solution
dbu

This error is received because are no users on the this remote LDAP group and as result the sync rule is failing to run.
This explains why user is not getting deleted.
Enable the option : Proceed with rule even when response empty . 

Check and let me know if it helped. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

8 REPLIES 8
dbu
Staff
Staff

Hi @akhan2 ,
Check if this option is enabled on the remote user sync rules : "Do not delete synced users when they are no longer found on the remote server" .

If enabled , disabled it and test again . 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
akhan2
New Contributor

Hi @dbu , This option is disabled, which means user should be removed  correct?

dbu

Yes if the option is disabled the user should be removed from the group in FortiAuthenticator.
Can you try a manual sync of the rule and check the logs if you see something related.

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
akhan2
New Contributor

I did a manual sync of the rule and can see something like : 

Sync rule ... was aborted because LDAP server returned an empty result.
How to fix this ?
dbu

It looks like there are no more users on this remote group. Can you verify ? 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
akhan2
New Contributor

Correct this is a test group with only one user. 
After I remove this user the group is empty, which means that sync rule should remove it also ?

dbu

This error is received because are no users on the this remote LDAP group and as result the sync rule is failing to run.
This explains why user is not getting deleted.
Enable the option : Proceed with rule even when response empty . 

Check and let me know if it helped. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
akhan2
New Contributor

Now it is clear. After enabling this option and run a manual sync of the rule user was removed from the group.
Thank you for help and explanation. 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors