FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
Jonathan_Body_FTNT
Article Id 196015

Description

This article explains how to understand LDAP error messages on the FortiMail unit and how to take basic steps to resolve the issue experienced.


Scope
All FortiMail versions
Solution

While querying an LDAP Server the following error messages could be printed in the Event Log section:
2009-12-01 14:23:52 smtp error mail mail NONE Milter (fas_milter): timeout before data read 2627
2009-12-01 14:27:49 LDAP query TIMEOUT for LDAP profile: ActiveDirectory
When receiving these error messages :

1. Edit the LDAP profile in use, section Advanced Options, and increase the query response timeout value as indicated below:

jbody_FD31526_AdvancedOptions.jpg

2. Check the Active Directory Logs on remote server for an indication of which parameter is causing the timeout. Fine tune the LDAP policies on the remote Active Directory Server as indicated in the following Microsoft knowledge base article:

 

If the FortiMail device continues to generate these messages after the suggested changes please open a support ticket on the Fortinet Support Portal.
Contributors