Hello Fortinet community,
I am experiencing an issue with LDAP user authentication failing on one Aruba switch using FortiAuthenticator as the RADIUS server. The admin local password login to the switch works fine, but LDAP users fail with the error logged on FortiAuthenticator:
"remote LDAP administrators authentication with no token failed: invalid password"
Notably, the same LDAP users authenticate successfully on other Aruba switches with the exact same FortiAuthenticator and LDAP policy configuration.
What I have checked/tried so far:
Verified RADIUS shared secret matches exactly on switch and FortiAuthenticator.
Confirmed LDAP users and groups are correct and working on other devices.
Compared Aruba switch configuration with working switches — config is identical.
Confirmed no special RADIUS attributes are set in FortiAuthenticator policies since other devices work fine.
Verified FortiAuthenticator can ping the problematic switch.
Ran FortiAuthenticator CLI diagnostics:
RADIUS client configuration verified.
LDAP server connectivity tested and OK.
LDAP user authentication tested on FortiAuthenticator CLI with same user — succeeds.
Confirmed no 2FA token required for these users causing failure.
Restarted FortiAuthenticator RADIUS service.
It seems like the issue is related to how authentication requests from this specific switch are processed by FortiAuthenticator, possibly some switch-specific interaction or policy filter. Any advice on what additional checks or logs I should focus on would be appreciated.
Thank you in advance.
Hi Sonihiren,
The error message ‘remote LDAP administrators authentication with no token failed: invalid password’ is too generic and does not provide sufficient details about the underlying issue.
Can you please enable the FortiAuthenticator Radius extended debug log?
https://<Fortiauthenticator ip or fqdn>/debug ---> Radius --> Authentication --> Max.log files size = 500MB and click Enter debug mode, and click Enter detailed debug mode.
Then reproduce the issue, write down the time when you did the test and the user name used for the test.
Please upload the logs for the specific attempt.
User | Count |
---|---|
2606 | |
1389 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.