Skip to main content
doncacciatoconsuting
Explorer II
March 19, 2025
Solved

FSSO - Loss of connectivity between FCTMobility Agent and FAC ?

  • March 19, 2025
  • 1 reply
  • 497 views

Goal is to create identity based FW policy.  We are looking at using FCT Mobility Agent and FAC Cloud. Trying to wrap my head around the impact in the event of a loss of connectivity anywhere in this path. SSOMA <--> FAC Cloud <--> Fortigate. 

 

How long by default does the Fortigate cache the user/ip correlation ? Any ideas ? 

Don

Best answer by jhussain_FTNT

Hi

By default, the FortiGate caches the user/IP correlation with FSSO for 8 hours. This is managed by the dead entry timer in collector agent and similarly the login expiry time under Fortinet SSO Methods > Fortigate settings

 

https://docs.fortinet.com/document/fortiauthenticator/6.5.2/administration-guide/712256/general-settings

 

Regards

Jamal Hussain

1 reply

jhussain_FTNT
Staff
Staff
March 23, 2025

Hi

By default, the FortiGate caches the user/IP correlation with FSSO for 8 hours. This is managed by the dead entry timer in collector agent and similarly the login expiry time under Fortinet SSO Methods > Fortigate settings

 

https://docs.fortinet.com/document/fortiauthenticator/6.5.2/administration-guide/712256/general-settings

 

Regards

Jamal Hussain

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.