Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mrwin
New Contributor

Windows 2003 active directory authentication (SSO) without agent

I' m trying to configure active directory user authentication (FSSO) in 600c with windows 2003 domain controller. User & Device -> Authentication -> LDAP Server Name : mydc Server Nape/IP : 192.168.0.5 Server Port : 389 Common Name Identifier : cn Distinguished Name : When I click the button on " Distinguished Name" nothing is listed in the popup box titled ' LDAP Distingiused Query'
4 REPLIES 4
Matthijs
New Contributor II

Did you check if ldap is working on the server? You can also just fill in the domain (for example dc=domain,dc=local) and try to go from there.
ruanbatista
New Contributor

What firmware version is running? Did you check de network connection between FGT and Win Server at port 389? If you use another LDAP reader software, can you list objects tree?
Information Security Consultant FCNSA Setrix Information Security Skype: ruan_diego
Information Security Consultant FCNSA Setrix Information Security Skype: ruan_diego
Dipen
New Contributor III

So you are simple trying to use LDAP Authentication and not Agentless FSSO [which is a new feature in FortiOS 5]. You can use Common Name Identifier as sAMAccountName and Bind Type as Regular. You just need to provide details of a Domain Admin Account in LDAP Configuration on Fortigate.

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
Vitor
New Contributor

Using this post, I´d like to know if can I set an username member of Domain Users? Why should be Domain admin? I don´t think this is the best way to give this kind of access. Thanks in advance.
Labels
Top Kudoed Authors