Skip to main content
andrewpearce
New Member
June 25, 2020
Question

FSSO (Single Sign-On to Windows AD) - No agent - 6.2.3

  • June 25, 2020
  • 0 replies
  • 1738 views

Hello All,

 

Trying to configure the fsso-polling with active directory to see if it will work better in our environment than the FSSO Agent.

 

This is the error I get:

 

Fortigate # diagnose debug fsso-polling detail 1 AD Server Status(connected): ID=1, name(10.0.x.x),ip=10.0.x.x,source(security),users(0) port=auto username=polling read log eof=1, latest logon timestamp: Thu Jun 25 15:01:05 2020

polling frequency: every 10 second(s) success(18), fail(0) LDAP query: success(0), fail(5) LDAP max group query period(seconds): 6 LDAP status: connected

 

Fortigate # 

di test authserver ldap LDAP polling *********

authenticate 'polling' against '10.0.x.x' succeeded! Group membership(s) - CN=NoLogonAccess,CN=Users,DC=test,DC=test,DC=ADS CN=Domain Admins,CN=Users,DC=test,DC=test,DC=ADS CN=Domain Users,CN=Users,DC=test,DC=test,DC=ADS

 

My LDAP queries are failing... even though I am able to authenticate with the credentials and there are no errors on the AD server.

 

Any help would be appreciated...

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.