Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
piaakit1210
New Contributor III

ssl vpn with LDAP connection failed

Dear All, 

 

        I have a question would like to ask, we have recently setup ssl vpn with LDAP, but after we input all the things and created firewall policy etc, and we found we wont be able to connect successfully and i did the use "test user credential" the result is failure, but the password is sure correct, any help would be appreicated, Thanks

 

Keith

1 Solution
piaakit1210
New Contributor III

found out is the AD server issue 

View solution in original post

6 REPLIES 6
SassiVeeran
Staff
Staff

Hi, 

- whether it is sslvpn web mode or tunnel mode?

- You may verify the setup sslvpn with ldap by referring to doc link here.

https://docs.fortinet.com/document/fortigate/6.4.2/administration-guide/115783/ssl-vpn-with-ldap-use...

- what is the error shows up when connection failed? any error screenshot or message.

- You may refer to kb article here to understand common issues.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-A-quick-guide-to-FortiGate-SSL-VPN-authent...

- Test credentials check from fortigate where it is succeeded.

FGT# diagnose test authserver ldap <LDAP server_name> <username> <password>

Where: <LDAP server_name> is the name of LDAP object on FortiGate (not actual LDAP server name!)

- run the debug command here to see any errors:-

# diagnose debug application sslvpn -1

# diagnose debug application fnbamd -1

# diagnose debug enable

mpeddalla
Staff
Staff

Hello  @piaakit1210 ,

 

Thank you for contacting the Fortinet Forum portal.

-Along with the steps provided by my colleague SassiVeeran, can you please check the below link if you are seeing a similar error "'Unable to logon to the server. Your username or password may not be configured properly for this connection."?

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-LDAP-user-authentication-Cred...

In most of the scenarios with the help of errors we can verify which settings are missing can you please confirm what error you are noticing and provide debug logs as well while testing

 

FGT# diagnose test authserver ldap <LDAP server_name> <username> <password>

Where: <LDAP server_name> is the name of LDAP object on FortiGate (not the actual LDAP server name!)

- run the debug command here to see any errors:-

# diagnose debug application sslvpn -1

# diagnose debug application fnbamd -1

# diagnose debug enable

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

vbandha
Staff
Staff

Hi @piaakit1210 ,

Regarding your query, you are getting error in test user credentials in LDAP. Is the test connectivity working?

If Test connectivity is working then the problem is in your LDAP settings. 

One of the common misconfiguration is the Common name identifier. Here is more information on that:
https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/102264/configuring-an-ldap-s...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-FortiGate-to-use-an-LDAP-...

You can try with both the settings: 'cn' and 'sAMAccountName' and check if the credential work.

Also check your credentials if they are entered correctly. Sometimes you need to enter the full username with domain name for it to work. 

 

If you test connectivity is also failing, then it is issue with connectivity to LDAP server. 

 

Regards,

Varun

dbu
Staff
Staff

What do you see in the logs of the firewall ? 
Is the authentication or the SSLVPN failing ?
You need to run the debugs to understand more : 
diag deb application fnbamd -1
diag deb application sslvpn -1
diag deb enable
Feel free to share any error or suspicious line from the debug commands. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
piaakit1210
New Contributor III

found out is the AD server issue 

mpeddalla

Hello @piaakit1210  ,

 

Thank you for confirming the solution.

If in the future any issues occur on SSL VPN or LDAP authentication. Please follow the above suggested steps.

 

Best regards,

Manasa.

Labels
Top Kudoed Authors