Skip to main content
jr3151006
New Member
August 9, 2011
Question

FSSO Agent on Console - Port 8000 or 8002?

  • August 9, 2011
  • 2 replies
  • 4667 views
Hi, I have a question regrading FSSO Agent, under WebConsole/User/Single Sign-on/FSSO Agent. - Must I inform the IP for all my DC´s and use port 8002 or 8000 port? - Must I use the LDAPSERVER option??? tks, Renato P

    2 replies

    Frosty
    New Member
    August 31, 2011
    I am a newbie when it comes to this stuff ... BUT ... I had pretty much the same issue as you I think, and after a lot of mucking around I settled on the following changes to Windows Firewall: allow the Collector on the DC where FSAE/FSSO is installed to use TCP port 8000; and allow the Agents on other DCs to use UDP on port 8002 I must confess I am not 100% certain about whether both INBOUND and OUTBOUND is needed for both of them, but that' s what I allowed and its working fine for me on 4.0 MR2 Patch Level 6.
    ede_pfau
    SuperUser
    SuperUser
    August 31, 2011
    It looks like the Collector uses TCP/8000 outgoing to access the Agents, and the Agents use UDP/8002 outgoing to report to the Collector. Both port numbers are fully configurable. So on the Collector DC the Windows firewall should allow OUTBOUND TCP/8000 and INBOUND UDP/8002, on the Agent servers should allow OUTBOUND UDP/8002 if the Collector is not polling. Easy to verfiy though. All that info is taken from the Authentication Guide resp. the FortiOS Handbook chapter on User Authentication.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!