Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chriskleve
New Contributor

SSL-VPN Problem after Upgrade to Firmware Version 5.0.5

Hello, after upgrade my Firmware Version to 5.0.5 I have a problem with the SSL-VPN. They Users are not able to login to the Fortinet SSL Website. The become the error message: Permission denied. If a take a look at the VPN Event log, I can see that SSL Login failes with the reson " no_matching_policy" . The users were grabed over LDAP Groups. The LDAP connection is fine..... I changed nothing else..... Has anybody an idea? regards Chris
6 REPLIES 6
chriskleve
New Contributor

Hi, just made some more tests.....If i create a local user and place him into the rules he can login and becomes access..... regards Chris
chriskleve
New Contributor

Hi, some more tests...... If I create a " local" LDAP User everything works fine..... If I use a AD Group with the Users it doesn' t work..... Seems to be a bug in the new firmware. Can anybody check this before I create a ticket? regards Chris
rwpatterson
Valued Contributor III

What was it working under before (version before upgrading)?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
chriskleve

Hi,
What was it working under before (version before upgrading)?
the Version before was 5.0.3. I made an direct Upgrade to 5.0.5 without the 5.0.4 Version.
I got it to work. Are you sure you' re using an LDAP group?
Yes I used Groups from our LDAP (AD) placed them into a Fortinet Group and gave this group the needed permissions. If I use Users from LDAP and place them into a Fortinet Group everything works......but when I try to use the Groups fronm LDAP lik before it doesn' t work anymore.... Regards Chris
billp

Chris, The revised Fortinet Cookbook has a step-by-step outline of the official Fortinet procedure on how to do this. That' s probably what tech support would have you review. I am just getting started on 5.0.x, so I am not familiar with anything that might have changed LDAP-wise from 5.0.3 to 5.0.5. If you want to check out the docs -- they' ve actually done a decent job on the latest cookbook -- it starts on page 252 on using LDAP with the VPN: http://docs.fortinet.com/cb/fortigate-cookbook-505-expanded.pdf One thing the docs don' t point out is that the Common Name Identifier on the LDAP server setup is frequently sAMAccountName and not CN for many businesses. The Authentication docs for 5.0 also have a section on debugging LDAP connectivity. Sorry -- I don' t have the commands handy at the moment.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
billp

I got it to work. Are you sure you' re using an LDAP group?

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Labels
Top Kudoed Authors