Probe lo que me dices, pero aun nada

, lo que si estube investigando por internet y ejecute un debug y me arrojo lo siguiente:
esto lo ejecute desde el Firewall y pasa sin problemasFW_LDAP # diagnose test authserver ldap serverLDAP fortinet Passw00rd
fnbamd_fsm.c[1010] handle_req-Rcvd auth req 26214402 for fortinet in serverLDAP
opt=27 prot=0
fnbamd_ldap.c[485] resolve_ldap_FQDN-Resolved address 192.168.1.254, result 192.168.1.254
fnbamd_ldap.c[234] start_search_dn-base:'DC=prueba,DC=local' filter:sAMAccountName=fortinet
fnbamd_ldap.c[1186] fnbamd_ldap_get_result-Going to SEARCH state
fnbamd_fsm.c[1322] poll_ldap_servers-Cont
fnbamd_ldap.c[268] get_all_dn-Found DN 1:CN=Fortinet LDAP,CN=Users,DC=prueba,DC=local
fnbamd_ldap.c[282] get_all_dn-Found 1 DN's
fnbamd_ldap.c[316] start_next_dn_bind-Trying DN 1:CN=Fortinet LDAP,CN=Users,DC=prueba,DC=local
fnbamd_ldap.c[1224] fnbamd_ldap_get_result-Going to USERBIND state
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 26214402
fnbamd_ldap.c[374] start_multi_attribute_lookup-Adding attr 'memberOf'
fnbamd_ldap.c[390] start_multi_attribute_lookup-base:'CN=Fortinet LDAP,CN=Users,DC=prueba,DC=local' filter:cn=*
fnbamd_ldap.c[1278] fnbamd_ldap_get_result-Entering CHKUSERATTRS state
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 26214402
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 26214402
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 26214402
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 26214402
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 26214402
fnbamd_ldap.c[417] get_member_of_groups-Get the memberOf groups.
fnbamd_ldap.c[441] get_member_of_groups- attr='memberOf', found 1 values
fnbamd_ldap.c[448] get_member_of_groups-val[0]='CN=SSLVPNUsers,CN=Builtin,DC=prueba,DC=local'
fnbamd_ldap.c[1292] fnbamd_ldap_get_result-Auth
acceptedfnbamd_ldap.c[1307] fnbamd_ldap_get_result-Going to DONE state res=0
fnbamd_auth.c[1543] fnbamd_auth_poll_ldap-Result for ldap svr 192.168.1.254 is SUCCESS
fnbamd_auth.c[1564] fnbamd_auth_poll_ldap-Skipping group matching
fnbamd_comm.c[112] fnbamd_comm_send_result-Sending result 0 for req 26214402
authenticate 'fortinet' against 'serverLDAP' succeeded!
memberof - CN=SSLVPNUsers,CN=Builtin,DC=prueba,DC=local Lo que viene a continuacion lo ejecute desde la VPN y vi que las ultimas dos lineas no me aparecen y vi las politicas pensando que era eso y no, estoy permitiendo todo hacia todos lados.FW_LDAP # fnbamd_fsm.c[1010] handle_req-Rcvd auth req 15138853 for fortinet in LDAPVPNUsers opt=256 prot=9
fnbamd_auth.c[228] radius_start-Didn't find radius servers (0)
fnbamd_auth.c[582] auth_tac_plus_start-Didn't find tac_plus servers (0)
fnbamd_ldap.c[485] resolve_ldap_FQDN-Resolved address 192.168.1.254, result 192.168.1.254
fnbamd_ldap.c[234] start_search_dn-base:'DC=prueba,DC=local' filter:sAMAccountName=fortinet
fnbamd_ldap.c[1186] fnbamd_ldap_get_result-Going to SEARCH state
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[268] get_all_dn-Found DN 1:CN=Fortinet LDAP,CN=Users,DC=prueba,DC=local
fnbamd_ldap.c[282] get_all_dn-Found 1 DN's
fnbamd_ldap.c[316] start_next_dn_bind-Trying DN 1:CN=Fortinet LDAP,CN=Users,DC=prueba,DC=local
fnbamd_ldap.c[1224] fnbamd_ldap_get_result-Going to USERBIND
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[374] start_multi_attribute_lookup-Adding attr 'memberOf'
fnbamd_ldap.c[390] start_multi_attribute_lookup-base:'CN=Fortinet LDAP,CN=Users,DC=prueba,DC=local' filter:cn=*
fnbamd_ldap.c[1278] fnbamd_ldap_get_result-Entering CHKUSERATTRS state
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[1096] fnbamd_ldap_get_result-Not ready yet
fnbamd_fsm.c[1322] poll_ldap_servers-Continue pending for req 15138853
fnbamd_ldap.c[417] get_member_of_groups-Get the memberOf groups.
fnbamd_ldap.c[441] get_member_of_groups- attr='memberOf', found 1 values
fnbamd_ldap.c[448] get_member_of_groups-val[0]='CN=SSLVPNUsers,CN=Builtin,DC=prueba,DC=local'
fnbamd_ldap.c[1292] fnbamd_ldap_get_result-Auth
acceptedfnbamd_ldap.c[1307] fnbamd_ldap_get_result-Going to DONE state res=0
fnbamd_auth.c[1543] fnbamd_auth_poll_ldap-Result for ldap svr 192.168.1.254 is SUCCESS
fnbamd_auth.c[1564] fnbamd_auth_poll_ldap-Skipping group matching
fnbamd_comm.c[112] fnbamd_comm_send_result-Sending result 0 for req 15138853
no me aparecen las ultimas dos lineas de la autenticacion

en los logg del firewall me dice lo siguiente:
Level
alert Sub Type
sslvpn-user ID
39426 Action
ssl-login-fail Message
SSL user failed to logged in