FSSO Fabric Connector: User Group Source - Collector Agent or Local?
We have one Fortiauthenticator functioning as a collector for three DC/TS agents. Currently on my gate I build FSSO groups locally, referencing an LDAP server, rather than building the groups on the collector and having them pushed to the gate. I'm wondering if there might be an advantage to creating the FSSO groups on the collector and pushing them. Is it more efficient to do use the collector in that way? Another question is - when I create local groups on the gate using LDAP as the source, is that group information getting pushed back to my FAC/Collector in some way, so it knows to monitor those groups? I'm looking for the most efficient or best practices approach to this setup. Thanks!