Skip to main content
Hassan97wsh
Staff
Staff
December 24, 2025

Technical Tip: FSSO CA stops syncing users with "packet size too big" error.

  • December 24, 2025
  • 0 replies
  • 264 views
Description This article describes how to resolve an issue where FSSO CA stops sending new logged on users with a debug error message 'packet size too big'.
Scope FortiGate configured with FSSO. The FSSO user filter is configured on the FortiGate (Local FSSO filter).
Solution

The cause of this issue is usually a high number of selected induvial users and user groups in the FortiGate local FSSO filter.

 

FSSO collector agent logs:

 

12/23/2025 00:04:48 [ 5740] FortiGate connection accepted, no auth check.
12/23/2025 00:04:48 [ 5740] FortiGate:FGXXXXXXXXXXXXXX-root connected on socket (4852).
12/23/2025 00:04:48 [ 5740] send AUTH, len:26
12/23/2025 00:04:48 [ 5740] ready to read from socket
12/23/2025 00:04:48 [ 5740] packet size too big:1073804
12/23/2025 00:04:48 [ 5740] reset connection 0

 

To resolve this issue, unnecessary users/groups must be deselected from the filter. Only users/groups that will have a firewall policy reference should be selected.

 

Related documents:

How to read FSSO CA debug logon events - Fortinet Community

FSSO group filtering based upon OU - Fortinet Community

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!