Created on
05-16-2025
08:53 AM
Edited on
05-16-2025
11:01 PM
By
syao
Description
This article describes the necessary configuration for FortiAuthenticator to act as Collector Agent in Polling mode.
Scope
FortiAuthenticator 6.6.2, FortiGate.
Solution
Step 1.
On the FortiGate, an external Connector is added pointing to the FortiAuthenticator.
The User/Groups can be seen or tailored as per the requirements.
Step 2.
Details to be added:
Adding these should have the server enabled and running.
Step 3.
Now, the event logs are seen on the FortiAuthenticator.
Navigate to Monitor -> SSO -> SSO sessions.
If there are specific events to be polled, it is possible to configure by List of Windows event log polling.
The following are useful logs in case there are any issues seen , in this example the FortiAuthenticator IP is 10.10.10.10.
Navigate to the FortiAuthenticator IP, https://10.10.10.10/debug, and look at Single Sign On -> FSSO Agent for any errors.
A successful snippet will show the following:
05/14/2025 17:43:08 [EEEA66C0] Domain Manager [DEBUG]: Found 'IT' in LDAP search in domain DC=startrek,DC=fortinet,DC=lab: CN=IT,OU=LABou,DC=startrek,DC=fortinet,DC=lab
05/14/2025 17:43:08 [EEEA66C0] Domain Manager [DEBUG]: Found user (IT) groups in domain startrek.fortinet.lab
05/14/2025 17:43:08 [EEEA66C0] Group Cache [DEBUG]: try to add startrek.fortinet.lab/IT
05/14/2025 17:43:08 [EEEA66C0] Group Cache [DEBUG]: try to add startrek.fortinet.lab/IT((null))
05/14/2025 17:43:08 [EEEA66C0] Group Cache [INFO]: added: startrek.fortinet.lab/IT
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.