03-18-2020 07:42 AM - edited 03-18-2020 07:43 AM
I am able to login through our firepower 1120 through VPN if i run LDAP through our AD.
If I run LDAPS instead it does not work.
See the attachment.
03-18-2020 08:00 AM
Hi,
Your problem is either the remote LDAP server does NOT run LDAPS (the service is not available/open, thus the error message), or port 636 is filtered someway along the path and the packets near reach the LDAPS server.
Regards,
Cristian Matei.
04-29-2020 05:23 PM
03-18-2020 08:43 AM
What version of FTD is this? Starting from 6.5, the FTD needs to trust the certificate presented by LDAPS server. 6.4 and below, this trust was not enforced. If you are on 6.5 and above, you need to install the CA certificate of the LDAPS server on the FTD as a cert enrollment object.
04-08-2020 03:43 PM
Hi Rahul,
do I understand correct, that I have to install the Root CA certificate of ldaps server in objects/pki/cert enrollment and add to devices/certificate on ftd device?
Regards,
04-17-2020 07:17 AM
That is correct. Unfortunately, this is not obvious from the FMC configuration.
01-31-2022 12:32 AM
Hello,
How I can install Root CA of LDAPS into Cert Enrollment? Do you have some manuals?
Thanks
01-31-2022 12:40 AM
01-31-2022 12:31 AM
Did you resolve this issue?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide