Skip to main content
GiuseppeB
Visitor III
July 2, 2024
Solved

FSSO logon mimatch

  • July 2, 2024
  • 3 replies
  • 1623 views

Hello everyone,

 

im testing a fsso solution where i have one machine that work as a collector agent, and another machine thath act as a DC, all the connection fortigate/fsso, fsso/dc and policy match work fine but i have a mismatch in the logon user list under the voice Type, which tell me is "DC-Agent" even if i have specified in the collector agent to work in pooling-mode.

 

I have restarted more than one time both dc and collector just to see if something change but nothing.

 

I dont know if this is just a bug or a real problem

 
 

Screenshot 2024-07-02 215816.png

BR,

 

Giuseppe

Best answer by pminarik

An already installed DC Agent will keep working and providing logon info to the Collector. Switching the Collector to polling doesn't disable DC Agents, it only enables polling as well.

If you want to get rid of the DC Agent info, either uninstall it from the DC completely, or edit its config to point it to a bogus IP:port instead of the correct Collector IP:port.

3 replies

EdwinCandelario
New Member
July 3, 2024

Hi!

  Verify that the user logon dc server  has the dc agent installed, so the fortigate will now who the user is.   Real world i use fortiems, because when you use another user in a user pc the fortigate will say that you are logged in the user pc. And all traffic from that pc will be assigned to you.  Elevated privilege is example when you do a run as administrator, that loggin will be catch by the fsso on the dc

GiuseppeB
GiuseppeBAuthor
Visitor III
July 3, 2024

Hello,

 yes DC has the agent installed, i have tried a lot of pc but the result dosent change.

 

Angelo

pminarik
Staff
pminarikAnswer
Staff
July 3, 2024

An already installed DC Agent will keep working and providing logon info to the Collector. Switching the Collector to polling doesn't disable DC Agents, it only enables polling as well.

If you want to get rid of the DC Agent info, either uninstall it from the DC completely, or edit its config to point it to a bogus IP:port instead of the correct Collector IP:port.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!