Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
padi
New Contributor III

Force FortiGate to use fallback password

Hi there,

I'm wondering If someone had this question/problem befor.

We recently had a misconfiguration in our AD structur, so that our service user for our FortiGate which is used for LDAP authentication, also for admins on the FortiGate, are moved to an other organisation unit. So the whole LDAP authentication on the FortiGate didn't work. First we recognices it because our users couldn't login over VPN and at troubleshooting, we found out, also the admins could not login on the FortiGate itself. Because the service account on FortiGate could not be found, because the DN of the user is changed.

 

While setup the admin users on the firewall we had to specify an Fallback-Password, if the FortiGate can't reach LDAP server. FortiGate never asks for the Fallback-Password, I think because, the FortiGate was able to reach LDAP servers but wasn't authorized to authenticate the users, because the service user couldn't be found in this OU.

 

Is this how it should work or should we be able to force the FortiGate to ask for this Fallback-Password?

We use FortiGate 200F v7.2.6

 

Padi

2 REPLIES 2
AEK
SuperUser
SuperUser

Hello

Fallback password should work when FG can't reach LDAP. So make a disconnection between FG and your LDAP (e.g.: deny FG IP in LDAP server's firewall) and then enter fallback password instead of LDAP password.

AEK
AEK
padi
New Contributor III

Hi AEK

I also tested this, at the moment where we had the outage. I disconnected all internal connection to the FortiGate, so also the connection to our DCs, but unfortunately it didn't worked, may I waited not enough, but FortiGate didn't ask for Fallback Password at this moment.

Labels
Top Kudoed Authors