Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor

SSL VPN Connection Error with LDAP

Hi,

 

last week we updated our FG cluster to FG200F with 7.4.5.

We had some problems but in general it seems quite OK. Only with SSL VPN we still have problems and we cnat get it functioning.

1. Connecting with Local User it works fine, I get the certificate window and I can login, no prob!
2. User from LDAP, connection to LDAP works fine, I can even test my credentials and OK but than connecting to the SSL VPN I dont geht the ceretificate pop up and after 48% I get Permission denied and -455

We did the same as in all other FGs. We imported the same remote certificate and everywhere it works. We checked groups and everything and it should be OK.

In System Events VPN I get:
Action ssl-login-fail
Reason sslvpn_login_unknown_user

 

What else can we try? It seems like the FG is not checking the certificate and we try with "Require Client certificate" and without and no change 

 

Thanks!

4 REPLIES 4
salemneaz
Staff
Staff

Hi,

 

Would you please try to follow the article reference given below;

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542

 

You can also try to connect the SSL VPN using the web portal bypassing the FortiClient.

If you are using LDAP user then you can follow the article reference given below to check the user.

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-LDAP-troubleshooting-and-d...

 

Salem
mle2802
Staff
Staff

Hi @RolandBaumgaertner72,

On FortiGate LDAP server config, can you try to test the username/password and see first of all if it is able to authenticate? 

Regards,

HiralShah
Staff
Staff

Hello @RolandBaumgaertner72 

 

Are you using any MFA for LDAP users?

Please check this document if forticlient is stopping at 48% it seems issue with MFA.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Possible-reasons-for-FortiClient-SSL...

 

Hiral
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors