Skip to main content
kcerb
New Member
September 24, 2014
Solved

FSSO in 5.2 problem

  • September 24, 2014
  • 3 replies
  • 30039 views

Hi, on Fortigate 100D ver 4.x we used a FSSO with FSSO Agent installed on Active Directory server with no trouble. After change firmware to 5.2 and FSSO Agent to 4.3.0159, users started complain about websites: sometimes websites opened and sometimes not. I decided to change SSO method to Polling. I configured everything with no luck. no users are shown in User & Device -> Monitor -> Firewall -> Show all FSSO Logons. The " diagnose debug authd fsso server-status" command shows only " Local FSSO Agent" !! which is not visible under User & Device -> Single Sign-On (I even deleted everything I created before): LDAP test: pass. When I add a SSO, the status is always grey X mark.

Best answer by Hassan_Fahmy

Solved by 

Execute Fsso Refresh 

add Selected group from FSSO agent @ AD 

add Selected group from Single sign on @ Fortigate FW

Done 

3 replies

kcerb
kcerbAuthor
New Member
September 25, 2014
OK, the greyed-out X mark solved: User must be " Administrators" group member. Now I can see users in monitor, but I can not see members of default " Domain users" group. This group is of course mapped in " User & Device -> User Groups" Does anybody have some idea about that?
Hassan_Fahmy
New Member
August 1, 2015

Same Issue any update !!!

 

 

Hassan_Fahmy
New Member
August 4, 2015

Solved by 

Execute Fsso Refresh 

add Selected group from FSSO agent @ AD 

add Selected group from Single sign on @ Fortigate FW

Done 

daac
New Member
October 6, 2015

solved

 

via cli

 

FORTI # show user fsso config user fsso     edit "Local FSSO Agent"         set ldap-server "LDAP_DA"         set server "127.0.0.1"     next end FORTI # config user fsso FORTI (fsso) # delete Local FSSO Agent

Dipen
New Member
October 8, 2015

Hi

 

First please stick to FSSO DC Agent Mode only (Forget Polling mode). Please do not have any LDAP Dependencies.

Firstly check "Currently Logon Users" in Collector Agent. Then check Group Filters in Collector Agent.

Finally check if FSSO Users are appearing in User >> Monitor >> Show FSSO Logons.