I'm trying to configure SSL-VPN users from an LDAP server with FortiToken. I have an issue: when a user tries to connect to SSL-VPN and is not defined in the group (the one connected to the LDAP), it bypasses the Active Directory group check and prompts for FortiToken anyway. (I know because even when I remove this user from the Active Directory group, the user can still connect.)
You mean the fortigate firewall? What is the version?
Have you done ldap debug to see what happens https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-LDAP-Troubleshooting-using-diagnose-... / https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-LDAP-troubleshooting-and-d... / https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-LDAP-authentication-errors... ?
Also by just googling I saw https://community.fortinet.com/t5/FortiGate/Technical-Tip-Description-of-CVE-2020-12812-bypassing-tw... and maybe there are are other well known issues.
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.