Skip to main content
networkingkool
New Member
November 3, 2015
Solved

FSSO agentless error with vDOM

  • November 3, 2015
  • 2 replies
  • 4204 views

Hello,

 

I configured with FSSO agentless with windows domain AD. My Fortigate WIFI 90D has root vDOM and WIFI vDOM.

When I do "diagnose debug fsso-polling detail" I see "most recent connection status: err: server can not be accessible"

My LDAP configuration is working correctly, I can fetch all OUs and Groups.

I think I have problem with source IP of vDOM. I have to config LDAP source-IP to one interface in root vDOM in order to make LDAP configuration working.

I wonder the same thing is happening with FSSO agentless. But I do not know how to fix this.

 

Could anyone have any ideas about my problem.

 

Thanks,

    Best answer by xsilver_FTNT

    Hi,

     

    just two suggestions ...

    1. use flow debug (see Fortinet KB) to trace how your packets flow to DC, might be blocked somewhere

    2. use standalone Collector Agent in Advanced mode instead of polling from FGT, much stable and variable/scalable solution

     

    Kind regards, Tomas

    2 replies

    xsilver_FTNT
    Staff
    Staff
    November 3, 2015

    Hi,

     

    just two suggestions ...

    1. use flow debug (see Fortinet KB) to trace how your packets flow to DC, might be blocked somewhere

    2. use standalone Collector Agent in Advanced mode instead of polling from FGT, much stable and variable/scalable solution

     

    Kind regards, Tomas

    networkingkool
    New Member
    November 8, 2015

    Hello,

     

    Thanks you, I 'm using Collector Agent in Standard mode now. It's good.

     

    Regards,

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!