Skip to main content
jboone
New Member
March 31, 2017
Question

FSSO TS Agent issue

  • March 31, 2017
  • 5 replies
  • 9933 views

Hello all, I just set up FSSO DC Agent and it is working correctly, when a user logs in to the their local system it notices their log in and associates the user with the traffic in the web filter of the fortigate. As expected it wasn't working with the terminal servers that we have so we installed the terminal server agent and got it configured. It appears to be working correctly in that when I look in the fortigate under Monitor > Firewall User Monitor users signed into the terminal server show up and the method is FSSO Citrix not Fortinet Single Sign On like the local system so its talking to the fortigate but when I look under the web filter traffic users are not associated with the traffic. If I look at the details of a request, the source port corresponds to the correct port range in the Collector Agent Logon Users List on the domain controller, so everything appears to be correctly set up but I can't figure out why the user isn't being associated with the traffic like I would expect.

 

We are using a Fortigate 100D with firmware version 5.4.1 FSSO Agent and TS Agent 5.0.0250

 

Any help is greatly appreciated to help get this working. 

    5 replies

    jboone
    jbooneAuthor
    New Member
    April 5, 2017

    Anyone have any thoughts? I'm at a loss. 

    MikePruett
    New Member
    April 5, 2017

    Are the users hitting a policy above or below the correct one?

     

    jboone
    jbooneAuthor
    New Member
    April 5, 2017

    I'm not sure how to tell if they are hitting a policy below it, but it is the very first policy so it should be hitting that one. It's the same policy as the local systems and it is working. 

    radar
    New Member
    May 2, 2017

    Probably (Microsoft and maybe FSSO Citrix agent) we having are the same symptoms with FSSO DC(Terminal  Server) agent installation on TS (MS) in 80 locations. From time to times, users put in or not to right web/applications data acces will be blocked (proxy users quest-no accesss, or proxy users -no internet access). 

    At this time service request with priority2 is confirmed, but we are back(long time weekend in Poland to date 08.05) to confirm, and we will  started  test the solutions  suggested by fortigate support team.(Thanks Petr).

     

    B.K

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!