Skip to main content
TuncayBAS
Explorer
January 23, 2019
Question

When FSSO is disconnected

  • January 23, 2019
  • 1 reply
  • 9000 views

On a system with FSSO user settings, is it possible for Fortigate to retain the last user logon list that was taken by the FSSO when it was disconnected, and to allow the outputs? When FSSO is disconnected, everyone appears to be a guest.

1 reply

xsilver_FTNT
Staff
Staff
January 23, 2019

Hi,

actually FortiGate (FGT hereinafter) is retaining the list.

When Collector Agent is seen as disconnected, unreachable, then FSSO user list is retained for 5 minutes before either of following occurrences happen ..

- connection to Collector Agent is re-established

- user list is verified with next Collector Agent in the list (if you do have multiple Collectors inside FSSO Agent on FGT)

- user list is wiped out from FGT

TuncayBAS
TuncayBASAuthor
Explorer
January 23, 2019

This 5 minutes, do we have a chance of extension?

xsilver_FTNT
Staff
Staff
January 24, 2019

Hi,

no direct chance of extending this timer.

It's hardcoded timer for graceful wipe out of the FSSO user list once FGT loose connection to Collector Agent, which is authoritative source of this list, not FGT.

To stop this timer from ticking, to keep users in list, and so keep them seen as authenticated, and so sessions running etc. etc. You 'just' need to make Collector Agent reachable and FGT connected to it again. Simple right ?