Hello everyone! The following messages appear in the logs in the FortiAuthenticator every minute. That is, the FortiAuthenticator both loses and finds the remote LDAP server again.
Please, tell me why this may occur. In the FortiAuthenticator CLI, diagnose netlink arp list, I see that the mac-address of my ldap server is either in the STALE state or in the REACHEBLE state.
Could there be a problem with arp?
Thanks
Hi Anatol
Stale state should mean there was no communication betwenn LDAP and FAC for a while.
Is LDAP server on the same subnet as FAC?
Can you try a continuous ping from FAC to LDAP and see if there are packet loss when the issue occurs?
Hi AEK! Thank you for your feedback. LDAP server and FAC are on different subnets with routing between them.
I start continuous ping from FAC to LDAP and packets are not lost for a long time, but at the same time messages "Status of remote server (LDAP) has been reset to offline-stale" and "Remote server (LDAP) become available" appear in the logs.
Hi Anatol
There is a known issue like yours that was fixed in 6.4.7 and 6.5.0.
848324 | Remote LDAP server constantly becomes offline-stale. |
Can you confirm your version is prior to that ones.
So, my version is v6.4.4, build1028. I will try to update it in the near future. Thank you!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
753 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.