System Admin Administrators
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903 275
http://docs.fortinet.com/ • Feedback
Configuring LDAP authentication for administrators
Lightweight Directory Access Protocol (LDAP) is an Internet protocol used to maintain
authentication data that may include departments, people, groups of people, passwords,
email addresses, printers, etc.
If you have configured LDAP support and an administrator is required to authenticate
using an LDAP server, the FortiGate unit contacts the LDAP server for authentication. If
the LDAP server cannot authenticate the administrator, the FortiGate unit refuses the
connection.
If you want to use an LDAP server to authenticate administrators in your VDOM, you must
configure the authentication before you create the administrator accounts. To do this you
need to:
• configure the LDAP server
• configure the FortiGate unit to access the LDAP server
• create a user group with the LDAP server as a member.
To view the LDAP server list, go to User > Remote > LDAP.
Figure 124: Example LDAP server list
To configure an LDAP server
1 Go to User > Remote > LDAP.
2 Select Create New or select the Edit icon beside an existing LDAP server.
3 Enter or select the following and select OK.
Create New Add a new LDAP server.
Name The name that identifies the LDAP server on the FortiGate unit.
Server Name/IP The domain name or IP address of the LDAP server.
Port The TCP port used to communicate with the LDAP server.
Common Name Identifier The common name identifier for the LDAP server.
Distinguished Name The distinguished name used to look up entries on the LDAP server.
Delete icon Delete the LDAP server configuration.
Edit icon Edit the LDAP server configuration.
Name The name that identifies the LDAP server on the FortiGate unit.
Server Name/IP The domain name or IP address of the LDAP server.
Server Port The TCP port used to communicate with the LDAP server.
Common Name
Identifier
The common name identifier for the LDAP server.
Distinguished Name The base distinguished name for the server in the correct X.500 or
LDAP format.