{{ secondMenu.name }}
FortiGate Parameter
FortiGate Parameter Description
Corresponding Sangfor NGAF Module/Parameter
Migration Notes
set server
LDAP/AD server address
Policies > Authentication > External Auth Server > LDAP Server
Directly corresponds; IP can remain the same
set cnid
User login attribute (e.g., sAMAccountName)
Policies > Authentication > External Auth Server > LDAP Server > User Attributes
Usually set as sAMAccountName
set dn
Base DN for queries, defines LDAP search scope
Policies > Authentication > External Auth Server > LDAP Server > Base DN
Fill in according to the original configuration
set type
LDAP type (regular means standard AD)
Default
set username
LDAP bind account for querying users
Policies > Authentication > External Auth Server > LDAP Server > Admin DN
Enter the full domain account, e.g., user@domain.com
set password
Bind account password (encrypted)
Policies > Authentication > External Auth Server > LDAP Server > Password
Must re-enter; encrypted passwords cannot be imported
set group-member-check
Check user group membership
User Group Mapping (LDAP Group Mapping)
Not Support
set secure
Enable LDAPS encryption
set port
LDAP service port
Policies > Authentication > External Auth Server > LDAP Server Port
389
set authtimeout
User authentication timeout (seconds)
Policies > Authentication > External Auth Server > LDAP Server > Timeout
Default 5 seconds; can keep the same