Authentication dropouts and user mis-reporting.
Hi,
We have a recently installed FortiGate 500e box. Firware version 5.4.8, build 4108.
Collector on single DC, agents on the others, policy in place to pick up logged in staff via group membership and allow them access to the web.
Seeing a lot of issues with users unable to access the web because they've dropped through the staff policy, and logging shows traffic from multiple users against a single source IP, at pretty much the same time.
Blocked traffic is TCP 443, definitely covered by the policy which is TCP 80/443.
Looks like an authentication issue, and the multiple users against a single machine is pointing the same way.
At a glance all the agents look fine, DC's aren't showing any errors, everything is sync'd fine.
Any ideas what this could be?
Thanks.