cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3437
Views
15
Helpful
8
Replies

Firepower 1120 LDAPS not working but LDAP is.

I am able to login through our firepower 1120 through VPN if i run LDAP through our AD.

If I run LDAPS instead it does not work.
See the attachment.

8 Replies 8

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

    

    Your problem is either the remote LDAP server does NOT run LDAPS (the service is not available/open, thus the error message), or port 636 is filtered someway along the path and the packets near reach the LDAPS server.

 

Regards,

Cristian Matei.

Looks like you’re running 6.5.x from the screenshot, so you can make sure the cert is added if that is the case.
You can also use the windows LDAPS tool to verify connection to your server with 636

Rahul Govindan
VIP Alumni
VIP Alumni

What version of FTD is this? Starting from 6.5, the FTD needs to trust the certificate presented by LDAPS server. 6.4 and below, this trust was not enforced. If you are on 6.5 and above, you need to install the CA certificate of the LDAPS server on the FTD as a cert enrollment object. 

Hi Rahul,

 

do I understand correct, that I have to install the Root CA certificate of ldaps server in objects/pki/cert enrollment and add to devices/certificate on ftd device?

 

Regards,

That is correct. Unfortunately, this is not obvious from the FMC configuration. 

Hello,

 

How I can install Root CA of LDAPS into Cert Enrollment? Do you have some manuals?

 

Thanks

Did you resolve this issue? 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card