Skip to main content
clarkg
New Member
May 13, 2013
Question

New groups created in AD not showing up in fortigate

  • May 13, 2013
  • 27 replies
  • 29740 views
I have 2 3600c' s in an active-active setup with firmware v5.0,build6216 (GA), and am also using vdom' s. I have noticed recently that when I create new groups in AD (global security groups or universal security groups) they are not showing up in my User & Device/User/ User Group/available members, under my fortinet single sign on. I have attached a pic of where I am talking about. I have a ticket with support open for this, but was just curious if anyone has seen an issue like this before and how you fixed it. We rebooted both fortigates this weekend, because we were testing a new backup generator. I have also rebooted the FSSO agent, and the server that it is on, to no avail.

    27 replies

    romanr
    New Member
    May 13, 2013
    Hi, if AD groups don' t show up instantly I often use the following CLI command to refresh the groups available in the Fortigate: diag debug auth fsso refresh-groups with diag debug auth fsso list you will get the loggend in users with their available groups. It is recommended to use the " Group Filter" feature on the FSSO agent to only show the used groups to the Fortigate! Maybe it is not included there! br, Roman
    clarkg
    clarkgAuthor
    New Member
    May 13, 2013
    The tech that was webex' ed in last week did run those commands, but that didn' t do anything. I created the group a week ago now, so I would think they would have shown up by now.
    romanr
    New Member
    May 13, 2013
    I created the group a week ago now, so I would think they would have shown up by now.
    Do you have a group filter on the FSSO agent, that maybe excludes this group? If it was newly created and has not been added there, then it won' t show up - only if you really show all groups to the FGT - which is not best practice, as you send some additional mem&cpu load to your Fortigate. br, Roman
    rwpatterson
    New Member
    May 13, 2013
    I had a similar issue I just solved this past weekend. Let me back up a bit... A few weeks past, I was running my 1000As in A-A mode. Internet browsing was spotty and FTP download speed sucked. After whining a bit here on the forums, a couple of members pointed me towards an old post that said that A-A mode has had issues in that respect. I changed my configuration to A-P and life has been great ever since. The problem was that the FSAE agent was still looking at the (now) backup unit for it' s user groups. It worked because they were cached, but user logins were being reported very slowly if at all. I discovered this last night, and pointed my FSAE agent to the primary unit and that took care of my issues. Perhaps you need to add the second unit under the FSSO Group Filter list (if you are using group filtering). This is where I noticed it was getting it' s group information from the backup unit. Give it a shot.
    clarkg
    clarkgAuthor
    New Member
    May 13, 2013
    I am not currently using group filtering. I don' t see a way to specify which FGT unit the fsso agent looks at. I have it monitoring my DC' s, and it says it' s seeing them all. On my 3600 cluster, under authentication single sign on, I have the correct primary agent IP listed, and I only have 1 fsso agent installed anyway.
    rwpatterson
    New Member
    May 13, 2013
    If your FGT doesn' t need to see all the groups, I would recommend you use the group filtering, and eliminate all the added baggage. Only pass the groups the FGT needs to see. Also helps a bit when debugging via CLI.
    romanr
    New Member
    May 13, 2013
    Can you do a: diag deb auth fsso list-users and have a look if the group shows up there with a user, that belongs to the group? I also remember once having had troubles with group names or DNs that were too long in total... They just didn' t show up correctly - maybe this info can also help you ... br, Roman
    clarkg
    clarkgAuthor
    New Member
    May 13, 2013
    Can you do a: diag deb auth fsso list-users and have a look if the group shows up there with a user, that belongs to the group? I also remember once having had troubles with group names or DNs that were too long in total... They just didn' t show up correctly - maybe this info can also help you ... br, Roman
    Ok. When I do that, I see the user and it does show he is a member of the group I created that is not showing up.
    romanr
    New Member
    May 13, 2013
    It is recommended to use the group filter in the FSSO agent to only make those groups visible to the Fortigate, which are being used to in the firewall! Otherwise you send a lot more information to the firewall, than it needs - which may result in perfomance loss! br, Roman
    romanr
    New Member
    May 13, 2013
    hm... and you don' t have any special characters on your group name... and this group is also from the same AD group type like the ones that work for you?
    clarkg
    clarkgAuthor
    New Member
    May 13, 2013
    hm... and you don' t have any special characters on your group name... and this group is also from the same AD group type like the ones that work for you?
    No special characters. In fact, this morning, I deleted the group, and recreated it with no spaces. And yes, I have many other global and universal security groups that work just fine.
    rwpatterson
    New Member
    May 13, 2013
    Perhaps the browser you are using is caching artifacts...since you can see it from the GUI.
    romanr
    New Member
    May 14, 2013
    I din' t have any further clue. Hope you get soon a good result with your support case. Please keep us updated on this trouble!! br, Roman
    Anne
    New Member
    May 15, 2013
    To my knowledge, the new groups you create in your AD do not automatically show up on the User & Device/User/ User Group/available members on the Fortigate. Those users need to generate a logon event which is passed onto Fortigate which populates the member List. Make sure that you logon your Domain with the new user accounts, followed by using " execute fsso refresh" and other debug commands mentioned above. Thanks Anne
    rwpatterson
    New Member
    May 16, 2013
    ORIGINAL: Anne To my knowledge, the new groups you create in your AD do not automatically show up on the User & Device/User/ User Group/available members on the Fortigate. Those users need to generate a logon event which is passed onto Fortigate which populates the member List. Make sure that you logon your Domain with the new user accounts, followed by using " execute fsso refresh" and other debug commands mentioned above. Thanks Anne
    The GROUPS are what' s not showing up. As a test, I created a group and then added it to my FSAE/FSSO allow filter. It showed up on my FGT about 60-90 seconds later. I just kept hitting the refresh icon on the ' User > Directory Service > Directory Service' window.
    clarkg
    clarkgAuthor
    New Member
    May 16, 2013
    As a test, I created a group and then added it to my FSAE/FSSO allow filter
    Ok, maybe I am missing someting. Sorry, I never setup the FSSO agent on the server, my network admin did that. Can someone show me where the fsso allow filter is. And which groups I would want to add to the allow filter? Do I just want to add any groups that I have a user identity policy for?
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!