Skip to main content
Somashekara_Hanumant
Staff & Editor
Staff & Editor
September 10, 2025

Technical Tip: Viewing the username/IP address on traffic logs using FSSO server logged on users

  • September 10, 2025
  • 0 replies
  • 594 views
Description This article describes how to view the username/ip address on forward traffic logs using FSSO logged on domain users, even though the FSSO user is not authenticated on the respective firewall policy.
Scope FortiGate, FSSO, Log.
Solution

To achieve this, FSSO should be configured:

 

fsso.JPG

 

Now, any user from the domain logs in to the AD server, then those users will be updated on the FortiGate user list as follows:

 

diagnose debug authd fsso list

IP: 10.108.3.14 User: NSE8-USER2 Groups: CN=NSE8-USER2,CN=USERS,DC=DXB-NSE8,DC=LAB+CN=USERS,DC=DXB-NSE8,DC=LAB+CN=DOMAIN USERS,CN=USERS,DC=DXB-NSE8,DC=LAB+CN=NSE8GRP,CN=USERS,DC=DXB-NSE8,DC=LAB+CN=USERS,CN=BUILTIN,DC=DXB-NSE8,DC=LAB Workstation: 10.108.3.14 MemberOf: CN=DOMAIN USERS,CN=USERS,DC=DXB-NSE8,DC=LAB CN=NSE8GRP,CN=USERS,DC=DXB-NSE8,DC=LAB CN=USERS,CN=BUILTIN,DC=DXB-NSE8,DC=LAB

 

Configure a firewall policy to allow the traffic from the internal interface to the external ISP interface (no FSSO User/Usergroup is selected under Source Option).

 

logs.JPG

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!