Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
siomyn
New Contributor III

Simple Bind Type

Hi, I already try to connect the fortigate with the LDAP server, there is an option bind Type that should be select, my question is what is the different between simple, regular search and anonymous .. the FortiOS Handbook 5.0 page 26 not clear enough for me. thanks

OMYN

Technical Consultant | Indonesia CCNP Security, Fortinet NSE 

OMYN Technical Consultant | Indonesia CCNP Security, Fortinet NSE
6 REPLIES 6
Rick_H
New Contributor III

For Active Directory I' ve always used a " regular" bind type with an unprivileged service account for permissions. Your mileage may vary with other LDAP systems.
siomyn
New Contributor III

thanks rick for your reply.. Is it mandatory using regular search if we use AD? My customer have a LDAP server, I use simple bind but the fortigate can not query the LDAP Server, when I click the query distinguish name, the 0 entries message appear. Authentication always failed if I attach to the policy.

OMYN

Technical Consultant | Indonesia CCNP Security, Fortinet NSE 

OMYN Technical Consultant | Indonesia CCNP Security, Fortinet NSE
pello
New Contributor II

Hi Siomyn, Best practice is to use regular when LDAP credentials transmitted in cleartext. As far as I know Windows 2003 and more recent operating systems deny replies on simple bind if a LDAP secure method is not enabled. Cheers
Eric_Lackey
New Contributor III

Try using the ldap debug command on the CLI or just set up an actual user against that server. Apparently, there' s a bug in the 5.0.3 release that causes the LDAP web set set up to fail when testing. We ran into the same thing, but we finally realized that it was actually working, but just throwing an error during testing.
Dipen
New Contributor III

You can use simple authentication if the user records are all under one dn that you know. If the users are under more than one dn, use the anonymous or regular type, which can search the entire LDAP database for the required user name. If your LDAP server requires authentication to perform searches, use the regular type and provide values for username and password. In Simple there is no binding or searching. • anonymous — bind using anonymous user search • regular — bind using username/password and thensearch • simple — simple password authentication without search

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
Rick_H
New Contributor III

Just to add a caveat to Dipen' s post: anonymous does not work with a properly (or default) configured Active Directory 2003 or later.
Labels
Top Kudoed Authors