Skip to main content
lukis2
New Member
March 27, 2026
Question

FAC/FSSO Ip address conflict

  • March 27, 2026
  • 2 replies
  • 142 views

Hi,

I use the FortiClient Single Sign-On Mobility Agent and I am facing an issue: FAC registers all user IP addresses.
Let’s consider two users: one connected remotely through VPN and one connected from the corporate LAN. The home network IP address of the remote user overlaps with the IP address of the user in the corporate LAN. As a result, one of the users is removed from FortiGate/FAC with the following error:
Internally logoff and removing FortiClient item 11024-HR.xxx.xxx:192.168.12.26 [xxx.xxx/j**bleep**h] (all IPs conflicting).
I believe that during the initial FAC/EMS configuration I chose the option to register all IP addresses, but now I cannot find this setting. I am not sure whether I am simply overlooking it or whether it disappeared after an update.
How should this be handled?

Regards,

Lukasz

2 replies

AEK
SuperUser
SuperUser
March 29, 2026

Hi Lukis

If you use VPN then you need to enable "Share all FortiClients" in EMS under menu "security fabric devices", since the FGT is not the gateway of you clients.

 

ems3.png

AEK
lukis2
lukis2Author
New Member
March 30, 2026

Here is my configuration:

image.png

 

 

AEK
SuperUser
SuperUser
March 30, 2026

The config looks fine.

Honestly I don't know if this can be fixed from EMS/FAC side. And I don't see another clean solution than resolving the IP conflict.

AEK