Skip to main content
unknown1020
Explorer III
June 23, 2023
Question

fsso agent on Windows AD

  • June 23, 2023
  • 2 replies
  • 2742 views

 I have a question, I have two computers FG-A and FG-B: The fsso agent was already configured and synchronized on the FG-A device.I recently configured the same fsso agent on the other FG-B and I already synchronize, the groups created in the AD are already shown on the FG-B.However, when the policies are created in the FG-B, it does not work, that is, it does not show any records.

note: there is an ipsec between the two FGs

Do you know what my mistake would be?

2 replies

lmarinovic
Staff
Staff
June 23, 2023

Hello,

 

So you have two computer with FSSO Collector Agent as I understood, computer with FG-A and FG-B.

Configuration is synced between collector agents.

Can you explain on what polices do you mean? And also where the records are not shown? On Collector Agent FG-B or on FortiGate later from FG-B?

 

Best regards,

 

Lazar

 

unknown1020
Explorer III
June 24, 2023

no, I'll explain.
I have an fsso agent already installed on my server and this agent is synchronized with my firewall A.
What I want is to configure the same fsso agent in my other firewall, I opened a case with tac and it recommended me to do it that way, in order not to install another fsso agent.
Since I have my ipsec, both firewalls communicate and my fg-b firewall has communication with the server where the agent is installed.

lmarinovic
Staff
Staff
June 26, 2023

Hello,

 

Then that is correct way. Both of FortiGate's will have the same database from same FSSO Collector Agent.

Let us know if you have more questions.

 

Best regards,

Lazar