Hi There,
I'm pretty new to Fortigate Firewall. I have a requirement to integrate the firewall for LDAP authentication.
Initially I have tried to add the LDAP server and perform the test connectivity and it failed. Later when I checked the firewall I noticed that the LDAP server is not reachable when I use the execute ping command. I have below questions.
[ol]
Thanks in Advance
Prashanth
Solved! Go to Solution.
To better control the interface the traffic is coming from I always specify the source IP.
config user ldap
edit (your server)
set source-ip (interface ip you want the traffic to come out of)
Now as long as that interface has access to where it is supposed to go you should be able to authenticate. Also, make sure you know if your ldap server requires secure ldap and that the account you are using to poll that server has the correct access to authenticate other users.
few things to check.
Routing if your FG and AD servers resides on diff vlan/segment
firewall policy
AD windows firewall settings.
Fortigate Newbie
Thanks for the reply.
Just to confirm incase if I'm adding adding a route to reach the LDAP server via the management interface, still the firewall policy is required to reach the AD server?
Thanks
If you mean by Management interface the hardware interface named "mgmt" in the Fortigate, then it is not intended for such a usage - connecting to LDAP, it is meant for out of band access to manage your Fortigate.
Fortigate will use IP address of the interface which it uses to reach LDAP server according to the routing table. So answer to 1. is "not dedicated Management but regular routing table and interface"
Outbound ping is enabled by default so it will work even without security rules in place. Inbound to Fortigate ping will work when 2 conditions are met:
[ol]And lastly - no, you don't need to add security rule for the Fortigate to reach LDAP server. But you do need proper route to reach LDAP.
To better control the interface the traffic is coming from I always specify the source IP.
config user ldap
edit (your server)
set source-ip (interface ip you want the traffic to come out of)
Now as long as that interface has access to where it is supposed to go you should be able to authenticate. Also, make sure you know if your ldap server requires secure ldap and that the account you are using to poll that server has the correct access to authenticate other users.
Thanks All for your kind help
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.