Skip to main content
hyder
New Member
May 5, 2025
Question

FSSO Collector Agent Working Partially – AD Groups Sync Inconsistent and Firewall Policy Usage Doubt

  • May 5, 2025
  • 4 replies
  • 1207 views
  • I have the FSSO Collector Agent installed on the AD server, using local polling (no DC Agent).

  • The Collector Agent service is running, and user logons are being fetched correctly.

  • However, in FortiGate, the FSSO connectors status shows as "Down", yet some AD groups are still fetched (e.g 1 and 7 groups).

  • Previously, when using local FSSO user group source, FortiGate fetched 65 groups, even while status showed disconnected.

  • Now, using Collector Agent method, only 7 and 1 groups are fetched from two external connectors pointing to the same AD IP and the policies using User group type FSSO did not get affected on changing the FSSO source group from local to Collector agent.

  • I’m confused about:

    1. How group fetching is working when the connection shows -Down.

    2. Whether it’s mandatory to create FortiGate User Groups and assign AD groups to them for policy use — or can we directly use AD groups in policy source?

    3. What causes this group fetching inconsistency and disconnection status, and how can I resolve it?

Can you help clarify these behaviors and recommend the proper setup?

4 replies

rbraha
Staff
Staff
May 5, 2025

Hi @hyder 

If connection shows down with external connector you will not be able to poll any group from collector agent, regarding this status down it may be many reasons, please check the guide below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Common-reasons-FSSO-status-shows-as-down-on-the/ta-p/193790

 

You can create an user group as FSSO type and assign the correct group imported from collector agent  then specify this user group in firewall policy.

hyder
hyderAuthor
New Member
May 8, 2025

Hi support,

 

Customer had collector agent installed but in FGT config they chose Local as user source group (LDAP). how does this change the concept and still user creating user groups with FSSO type and adding the groups pulled locally how?

rbraha
Staff
Staff
May 9, 2025

Hi @hyder 

It's suggested that user groups to be collected on FGT from collector agent ,instead of FGT pulling locally through ldap server ,which will cause more load/ resources to poll this info.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!