FSSO Collector Agent Working Partially – AD Groups Sync Inconsistent and Firewall Policy Usage Doubt
I have the FSSO Collector Agent installed on the AD server, using local polling (no DC Agent).
The Collector Agent service is running, and user logons are being fetched correctly.
However, in FortiGate, the FSSO connectors status shows as "Down", yet some AD groups are still fetched (e.g 1 and 7 groups).
Previously, when using local FSSO user group source, FortiGate fetched 65 groups, even while status showed disconnected.
Now, using Collector Agent method, only 7 and 1 groups are fetched from two external connectors pointing to the same AD IP and the policies using User group type FSSO did not get affected on changing the FSSO source group from local to Collector agent.
I’m confused about:
How group fetching is working when the connection shows -Down.
Whether it’s mandatory to create FortiGate User Groups and assign AD groups to them for policy use — or can we directly use AD groups in policy source?
What causes this group fetching inconsistency and disconnection status, and how can I resolve it?
Can you help clarify these behaviors and recommend the proper setup?
