Fortigate FSSO Agent - Logon/Logoff events
I have configured FSSO for a client in conjunction with and explicit proxy on a Fortigate FW and works well. Testing has highlighted a potential issue I wasn't aware of, in that when a user locks their workstation, the FG is sent a logoff event from the collector agent. Result of this is that the workstation can no longer authenticate through the explicit proxy as there is no user/IP entry due to the logoff event. Obviously whilst the workstation is locked the user doesn't need to browse the web, however the logs show that applications are still trying to access the internet, such as MS Office365 but are being denied.
When the user unlocks the workstation a logon event is sent to the FG and the user can browse again through the proxy. There seems to be a small delay in the FG getting the logon event and then authenticated through the proxy, which impacts the user experience.
I've been searching to find out whether this is expected behaviour but can't find anything related. Windows event IDs for workstation lock/unlock are 4800 and 4801 but these aren't monitored from what I can see.
Does anyone know if there is any way of preventing this behaviour occurring with the lock/unlock causing logoff/logon events?
