Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rwpatterson
Valued Contributor III

FAZ and LDAP

How the hell do you connect the two? I used the exact same configuration as the FGT but it doesn' t want to cooperate. Any and all help is appreciated. (I though that if maybe I got out of the stone age and upgraded, the problem would go away. It didn' t. Now I have the indexer daemon running at 100%... Bleah....)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
7 REPLIES 7
billp
Contributor

Bob, I don' t use LDAP on my FAZ, so can' t help you on that point. But isn' t the indexer daemon is supposed to run at %100 when idle?

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
rwpatterson
Valued Contributor III

LOL! I' m not sure. Didn' t RTFM yet. My goal with this thing is to get reports based on the AD user. So far I' m stuck with IP addresses only, but we use thin clients. The IP addresses vary.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
billp
Contributor

Hmm. Indexer is supposed to run at 100%, so you are good there. On our FAZ reports, the IP addresses are resolved to usernames by the Fortigate before it sends the logs. This is eDirectory, though, so might be different.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
rwpatterson
Valued Contributor III

I run reports, I get user names. When I want to run a report by a single user (even one that' s in the reports), I cannot. By the way, I' m hot using the SQL database, just the standard.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
billp
Contributor

For my reports, I just set the user field in the Report Filters to whatever the user name is in log files. For some users that logon via FSSO, it' s the fully-qualified LDAP name like CN=Joe,O=company, etc. For users that don' t auth against FSSO, it' s just joe. I am using the SQL database hosted on another server. My 100B is just too slow for words and this was a cheap way to speed it up.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
rwpatterson
Valued Contributor III

Hmmm FQDN. Didn' t think of that. I' ll give it a shot.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
billp
Contributor

I am not certain, but it' s possible it might also be case sensitive. I try to match the exact case I see in the raw log files.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Labels
Top Kudoed Authors