LDAP is not designed to be an auth protocol, if you can use RADIUS for your firewall to auth against (even if it is using the same server/database), you will have an easier life. Some people may find this statement controversial, but we will have to agree to disagree.
Regardless of protocol however, you will need to look at your firewall and server logs, your client errors aren't going to lead you anywhere useful.