Skip to main content
jamestiberius
Explorer
July 24, 2023
Solved

FSSO type question

  • July 24, 2023
  • 2 replies
  • 1414 views

we have FSSO Agent running on member server, it pollss the AD server.

when looking at Show Logn Users, most of the users show as Type DC-agent, but a few are showing as type EventLog.

can someone tell me why?  my understanding of our setup is it polls the AD server, and those users in certain AD groups are allowed internet based on the group they are in.

so what is EventLog type in that case?

Best answer by Anonymous_User

Hi @jamestiberius ,

There are 2 method for FSSO.
Fortigate itself poll from the AD server

vs
Fortigate poll from the DC-Agent which installed on the server.

 

In your case, maybe you have a combination of it.

2 replies

New Contributor III
July 25, 2023

Hi @jamestiberius ,

There are 2 method for FSSO.
Fortigate itself poll from the AD server

vs
Fortigate poll from the DC-Agent which installed on the server.

 

In your case, maybe you have a combination of it.

Markus_M
Staff & Editor
Staff & Editor
July 25, 2023

More info on polling and which node understands what as well as which event IDs are used:

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Windows-event-IDs-used-by-FSSO-in-WinSec-polling/ta-p/189910