Skip to main content
FAPM
New Member
August 30, 2017
Question

FSSO / AD ERROR LOG

  • August 30, 2017
  • 1 reply
  • 13405 views

Hi,

 

Do you have any idea about the origin of the logs below? Fortigate or DC ?

I have these logs every 20 to 30 minutes. It works but apparently it can no longer communicate with the dc then reinitializes the connection.

No problems in DC, either in users or on the network ...

thanks ALL.

 

FA.

 

FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: bind -> connected 2 12:06:24 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: begin -> bind 3 12:06:24 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: init -> begin 4 12:06:19 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: err: server is not accessible -> init 5 12:06:19 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: connected -> err: server is not accessible 6 11:50:24 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: bind -> connected 7 11:50:24 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: begin -> bind 8 11:50:24 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: init -> begin 9 11:50:19 FSSO-polling-LDAP-server FSSO-polling-LDAP-server status changes: err: server is not accessible -> init

 

 

    1 reply

    xsilver_FTNT
    Staff
    Staff
    August 30, 2017

    It looks like FortiGate's event log about local FSSO poller from FortiGate doing polling towards some DCs.

    You should see the complete log (as above mentioned is shortened) in FortiGate / Event logs /

    probably as type="event" subtype="user" level="notice".

    FAPM
    FAPMAuthor
    New Member
    August 30, 2017

    Hi Tomas,

    We get no more info :

    Log Details  Action FSSO-polling-LDAP-server  Time 13:10:22  Device Name xx  Level notice  Log Description FSSO Active Directory server authentication status  Log ID 0102038033  Message FSSO-polling-LDAP-server status changes: connected -> err: server is not accessible  Sub Type user  Type event  Virtual Domain root  User / XAUTH User xx
    xsilver_FTNT
    Staff
    Staff
    August 30, 2017

    try to collect log or have a loog to log details in GUI,

    eventID 0102038033 should contain also 'server' key with value pointing to FSSO Agent name in config.

    Or simply check the config for agents, maybe you have just one in VDOM root.

    It looks like your FGT is unable to poll, access, the DC.

     

    1. do you have agent connected ? FGT-VM64-1 (root) # diag debug reset FGT-VM64-1 (root) # diag debug enable FGT-VM64-1 (root) # diag debug authd fsso server-status FGT-VM64-1 (root) # Server Name                          Connection Status     Version -----------                          -----------------     ------- Local FSSO Agent                     connected             FSAE server 1.1 2. do you see any users or you see 0 user ? FGT-VM64-1 (root) # diag debug fsso-polling user FSSO: vd index(0), AD_Server(192.168.32.21), Users(0) 3. if zero users, what is the poller status ? do you have AD connected ? do you have successful pollings ? does your user in AD fit in group filter ? FGT-VM64-1 (root) # diagnose debug fsso-polling detail