Hot![FortiGate 60D] Notification: Can't contact LDAP server

Author
dzt0
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/04/29 03:31:27
  • Status: offline
2019/04/29 03:48:20 (permalink)
0

[FortiGate 60D] Notification: Can't contact LDAP server

Dear all,

Please let me know why don't ping from FortiGate Router to Active Directory server?
But ping from Active Directory server to FortiGate Router is OK.
 
I trying to setup LDAP server but get the error: "Can't contact LDAP server". 
I tried it all. Suggest me the next step. What should I check from?
 
 
 

Attached Image(s)

#1

4 Replies Related Threads

    ede_pfau
    Expert Member
    • Total Posts : 6028
    • Scores: 480
    • Reward points: 0
    • Joined: 2004/03/09 01:20:18
    • Location: Heidelberg, Germany
    • Status: offline
    Re: [FortiGate 60D] Notification: Can't contact LDAP server 2019/04/29 06:47:08 (permalink)
    0
    Probably the source address for ping/LDAP is not correct.
    Test with ping first.
    exec ping-option source a.b.c.d
    sets the FGT's source address to one of it's interfaces. You cannot choose an arbitrary address, that is.
    In the CLI there is a "source-address" setting for LDAP as well, look in "config auth ldap".

    Ede

    " Kernel panic: Aiee, killing interrupt handler!"
    #2
    xsilver_FTNT
    Expert Member
    • Total Posts : 430
    • Scores: 91
    • Reward points: 0
    • Joined: 2015/02/02 03:22:58
    • Status: offline
    Re: [FortiGate 60D] Notification: Can't contact LDAP server 2019/05/02 02:10:01 (permalink)
    0
    Have you checked following ..
    - routing on FGT, and all the way to LDAP .. any asymmetry or routing issue ?
    - firewall on the way not allowing ICMP from FGT but allowing it from LDAP ?
    - any firewall on LDAP/AD itself ?
    - on FGT what's  on packet capture .. any ingress of ICMP ?
    - on FGT any local in policy preventing that ?
    - on FGT what's in flow debug ?
     
    I guess that some of those steps will give you a hint what's going on.

    Kind Regards,
    Tomas
    #3
    dzt0
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/04/29 03:31:27
    • Status: offline
    Re: [FortiGate 60D] Notification: Can't contact LDAP server 2019/05/06 21:44:35 (permalink)
    0
    I try ping-options, it works
    My Active Directory server is 10.0.1.1
    I need to check the Source address on FGT, right? How to check it?
     

    #4
    xsilver_FTNT
    Expert Member
    • Total Posts : 430
    • Scores: 91
    • Reward points: 0
    • Joined: 2015/02/02 03:22:58
    • Status: offline
    Re: [FortiGate 60D] Notification: Can't contact LDAP server 2019/05/07 05:09:09 (permalink)
    0
    how about packet capture of the outgoing traffic?
    for example:  diag sniff pack any 'host 10.0.1.1 and icmp' 4 0 a
     
    More on basic tools
    https://kb.fortinet.com/k...amp;externalId=FD30038

    Kind Regards,
    Tomas
    #5
    Jump to:
    © 2019 APG vNext Commercial Version 5.5