Created on 12-16-2023 07:27 AM Edited on 02-26-2024 05:25 AM By Kate_M
Dear All,
I have a question would like to ask, we have recently setup ssl vpn with LDAP, but after we input all the things and created firewall policy etc, and we found we wont be able to connect successfully and i did the use "test user credential" the result is failure, but the password is sure correct, any help would be appreicated, Thanks
Keith
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
found out is the AD server issue
Hi,
- whether it is sslvpn web mode or tunnel mode?
- You may verify the setup sslvpn with ldap by referring to doc link here.
- what is the error shows up when connection failed? any error screenshot or message.
- You may refer to kb article here to understand common issues.
- Test credentials check from fortigate where it is succeeded.
FGT# diagnose test authserver ldap <LDAP server_name> <username> <password>
Where: <LDAP server_name> is the name of LDAP object on FortiGate (not actual LDAP server name!)
- run the debug command here to see any errors:-
# diagnose debug application sslvpn -1
# diagnose debug application fnbamd -1
# diagnose debug enable
Hello @piaakit1210 ,
Thank you for contacting the Fortinet Forum portal.
-Along with the steps provided by my colleague SassiVeeran, can you please check the below link if you are seeing a similar error "'Unable to logon to the server. Your username or password may not be configured properly for this connection."?
In most of the scenarios with the help of errors we can verify which settings are missing can you please confirm what error you are noticing and provide debug logs as well while testing
FGT# diagnose test authserver ldap <LDAP server_name> <username> <password>
Where: <LDAP server_name> is the name of LDAP object on FortiGate (not the actual LDAP server name!)
- run the debug command here to see any errors:-
# diagnose debug application sslvpn -1
# diagnose debug application fnbamd -1
# diagnose debug enable
Best regards,
Manasa.
If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.
Hi @piaakit1210 ,
Regarding your query, you are getting error in test user credentials in LDAP. Is the test connectivity working?
If Test connectivity is working then the problem is in your LDAP settings.
One of the common misconfiguration is the Common name identifier. Here is more information on that:
https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/102264/configuring-an-ldap-s...
You can try with both the settings: 'cn' and 'sAMAccountName' and check if the credential work.
Also check your credentials if they are entered correctly. Sometimes you need to enter the full username with domain name for it to work.
If you test connectivity is also failing, then it is issue with connectivity to LDAP server.
Regards,
Varun
What do you see in the logs of the firewall ?
Is the authentication or the SSLVPN failing ?
You need to run the debugs to understand more :
diag deb application fnbamd -1
diag deb application sslvpn -1
diag deb enable
Feel free to share any error or suspicious line from the debug commands.
found out is the AD server issue
Hello @piaakit1210 ,
Thank you for confirming the solution.
If in the future any issues occur on SSL VPN or LDAP authentication. Please follow the above suggested steps.
Best regards,
Manasa.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.