I have an issue with explicit proxy authentication with NTLM with LDAP lookup to AD - in summary our user UPN in AD does not match our domain name and thus LDAP lookup fails Our domain is exampleAD.com My user is user1@exampleAD.com My UPN is user1@example.com If I change my UPN back to user1@exampleAD.com the user authentication in explicit proxy then works, but we have a requirement (Office 365) for our UPN to match our email domain name, thus must remain different to domain user name. Any ideas what we can do to resolve?
Thanks in advance
The log details if it helps are below - but not sure this is relevant as I know the workaround is to change the UPN.
GeneralDate2019/01/21Time11:25:51Virtual DomainrootLog DescriptionExplicit proxy user group query failedSourceIP10.10.10.10Useruser1@exampleAD.comGroupN/ADestinationIP212.58.249.208Host Namewww.bbc.co.ukActionActionNTLM-authPolicy0StatusfailureReasonGroup information query failedAuthentication ProtocolHTTP(10.10.10.10)SecurityLevel EventMessageUser failed in group information query
Hi,
Did you try with group filters under "config user ldap"?
Anyone looking in the future - I fixed the issue - change domain-name under domain-controller to match your UPN the users have set and all seems to work OK
config user domain-controller edit "domain.com" set ip-address 10.10.10.10 set domain-name "domain.com" set ldap-server "DC01" next end
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.