Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xavier_ruch
New Contributor

WebMail access denied

Hello,

 

We have a FortiMail v.6.0.3 VM Appliance (Gateway mode) mainly linked to Active Directory users and Exchange emails. We've setup LDAP Profiles and everything works or worked perfectly, filtering, quarantine, webmail...

 

Suddenly WebMail doesn't work anymore and users get an invalid login error when trying to access. We've of course double checked the credentials and everything is fine as testing (in the LDAP Profile) the email address and password works fine (Bind successfull).

 

We are surely missing something and any help would be greatly appreciated.

9 REPLIES 9
crispy
New Contributor

Are you sure its not the same issue as mentioned in [link]https://forum.fortinet.com/tm.aspx?m=168438[/link]

http://www.2000cn.com.au
xavier_ruch

Hello,

 

Thanks for your reply. This is definitely not the same issue as the quarantine link works perfectly in the reports.

crispy

Are you getting any errors logged in the system log on the FM?

 

Check that your resource profile has user account status and webmail access enabled and that it is applied to the domains.

http://www.2000cn.com.au
xavier_ruch

No errors in the logs and ressource profiles all have webmail enabled.

 

But still getting the authentication error at webmail login (tested with several different accounts)

 

crispy

Are all the accounts your having issues with on the same domain or different domains?

http://www.2000cn.com.au
xavier_ruch

Different domains, different locations, different Windows Server Standard versions (2012 and 2016)...

crispy

Sounds like you should open a tac case.

 

Only other thing I can think of is a 'diag db rebuild' in case you have a corrupt database, but it sounds like everything else is working.

http://www.2000cn.com.au
xavier_ruch

Indeed I am going to open a ticket.

 

Many thanks for your appreciated time, cheers !

bhh

One thing to check and which was causing the issue for us. If you are using an LDAP profile for authentication, it needs to be present in all rules, even rules that don't need it, otherwise it did not work and causes an error when accessing webmail.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors