Solved
Issue with FSSO Agent Communication on secondary DC
Hello All,
I have Fortinet Single Sign-On (FSSO) Agent installed in DC Agent mode on both of my domain controllers (DC01 and DC02).
Observations:
- When a user logs into the network with DC01 as their logon server:
- The user appears in the Show Logon Users list on the FSSO agent.
- The collector forwards this information to FortiGate, and the user is also visible in the FSSO user list on FortiGate.
- When a user logs in with DC02 as their logon server:
- The user appears in the Show Logon Users list on the FSSO agent on DC02.
- However, this information is not forwarded to FortiGate.
Troubleshooting Steps Taken:
- Verified that FortiGate can connect to both domain controllers on TCP/8000 without any issues.
- Confirmed that the registry path Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FSAE\DCAgent\CA contains the IP addresses of both DC01 and DC02 on both servers.
- Confirmed the IP address of DC02 as a secondary-server in the FortiGate configuration.
- Restarted FSSO services on both DC01 and DC02.
- De-authenticated the user list on FortiGate.
Current Setup:
- FSSO Agent version: 5.0.0.318 (installed on both servers).
- FortiOS version: 7.2.10.
Questions:
Is there anything else I can check to resolve this issue? I have not yet reinstalled the FSSO agent on DC02.
Any guidance would be greatly appreciated.
