Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dkester
New Contributor

ldaps fails when circuit fails over to secondary.

My Fortigate 1800 is configured with with 2 circuits Xtel primary and Cogent secondary when I fail over to secondary by disabling route for primary circuit LDAPS does not function.   All of my other connections work with the exception of LDAPS.   I am running 7.2 code

5 REPLIES 5
smaruvala
Staff
Staff

Hi,

 

- What do you see in traffic logs? Do you see the packet sent and received counts as non-zero?

- Have you tried to take packet capture for the communication? Do you see any issue with the SSL handshake?

 

Regards,

Shiva

Toshi_Esumi
SuperUser
SuperUser

Make sure you have below in global config. SNAT sessions are very sticky.

config system global
  set snat-route-change enable  (by default it's disabled)
end

 

Toshi

davekester

snats are enabled   I have to sites that use port 636 to complete authentication and both work until I fail over to the other circuit is there anything else that needs configuration for second circuit to work with ldaps?   

Toshi_Esumi

Has it ever worked over the secondary circuit? My guess is not. Are you sure the server side accept your connection from the IP on the second circuit?
I would take a pcap toward the server IP on the second interface. Then check packets what the FGT is sending and receiving. My guess is the FGT is sending them out but receiving a rejection.

 

Toshi

davekester

Thanks I think your right to put it on the receiving server.   I am going to send them the logs.

Labels
Top Kudoed Authors