FSSO Advanced Mode does not work (sometimes)
Hi,
im using OS 5.2.10 in my Firewallcluster, i have 2 DC with a Windows2012 Domain, everyone got the Forti SSO Agent in Version 5.0.244 installed. Basicly it is working. But sometimes the users have no Access to the Internet, this occure only at Laptop and PC User, our Terminaluser (with TSAgent) didnt have any issue.
I have set the Log to Debug Mode and found that
07/05/2017 16:56:06 [ 1896] not in filter: last user:dreimann user:dreimann
07/05/2017 16:56:06 [ 1896] not infilter:lastgroup:CN=dreimann,OU=Inhaus_WO_keinCOS,OU=Inhaus_WO,OU=Inhaus_Laptop,OU=Win_Clients,OU=Users_Computers,DC=xxxx,DC=wortmann,DC=com+OU=Inhaus_WO_keinCOS,OU=Inhaus_WO,OU=Inhaus_Laptop,OU=Win_Clients,OU=Users_Computers,DC=xxxx,DC=wortmann,DC=com+OU=Inhaus_WO,OU=Inhaus_Laptop,OU=Win_Clients,OU=Users_Computers,DC=xxxx,DC=wortmann,DC=com+OU=Inhaus_Laptop,OU=Win_Clients,OU=Users_Computers,DC=xxxx,DC=wortmann,DC=com+OU=Win_Clients,OU=Users_Computers,DC=xxxx,DC=wortmann,DC=com+OU=Users_Computers,DC=xxxxx,DC=wortmann,DC=com+CN=Domänen-Benutzer,CN=Users,DC=xxxx,DC=wortmann,DC=com+CN=AS/400_Benutzer,CN=Users,DC=xxxx,DC=wortmann,DC=com+CN=Office-Vorlagen,OU=office,OU=Benutzergruppen,DC=xxxxDC=wortmann,DC=com+CN=mca,CN=Users,DC=xxxx,DC=wortmann,DC=com+CN=sonicwall,CN=Users,DC=xxxDC=wortmann,DC=com+CN=proxy_full_http_access,OU=proxy,OU=Benutzergruppen,DC=xxxx,DC=wortmann,DC=com+CN=notebookuser,CN=Users,DC=xxxx,DC=wortm...
07/05/2017 16:56:06 [ 1896] not in filter: last user:dreimann user:dreimann
I suggest not in Filter means this User is not in the AD Group (but she is) if she log off and on it works, the user is in 45 Groups, maybe thers a max Group Check ? u see the "..." at the end of the Group lookup, this is going through all of our Users.
Any Hints ?
Cheers
Michael
