Description
This article expands upon the Tiered Architecture feature noted here:
https://docs.fortinet.com/document/fortiauthenticator/6.0.0/administration-guide/568338/tiered-archi...
It illustrates in greater detail the purpose of tiered architecture, how to set it up, and some known limitations.
Solution.
FortiAuthenticator includes a feature called Tiered Architecture for more complex Single-Sign-On deployments across multiple FortiAuthenticators.
Tiered Architecture allows for FortiAuthenticators to share SSO session details (username, user groups, login source, etc) between them without requiring much additional setup; a FortiAuthenticator may thus track Single-Sign-On sessions for domains or locations it is not directly associated with.
This is done by defining FortiAuthenticators as supplier or collector nodes to each other; the supplier node will send SSO session details to the collector node. This may be chained; FortiAuthenticator1 is supplier node to FortiAuthenticator2, which in turn is supplier to FortiAuthenticator3, etc.
1) Enabling Tiered Architecture.
This is done under Fortinet SSO Methods -> SSO -> General, with the option 'Enable hierarchical FSSO tiering'. A port may be defined here on which FortiAuthenticator will listen as collector node.
Default is port 8003.
Supplier server accepting one connection from 10.191.19.14(sock 5)On supplier nodes.
Supplier FAC-test(FAC-xxxxxxxxxx) connected from 10.191.19.14
Received 1 event(s) from supplier: FAC-test/10.191.19.14
supplier LOGON [details]
Logon Cache [INFO]: Added new logon, workstation:[…] ip:[…] user: […]
Load collector: test-FAC2 10.191.19.35:8003 FAC-xxxxxxxxxx,(null)Note:
Collector: name=test-FAC2 address=10.191.19.35:8003 SN=FAC-xxxxxxxxxx
Connected to collector FAC-xxxxxxxxxx at 10.191.19.35:8003
send collector HELLO
process collector HELLO
Send all logons (total 1) in vdom 'Default' to collector: 10.191.19.35:8003
Send LOGON_INFO (640 bytes) to collector: 10.191.19.35:8003
Send LOGON_EVENT (26 bytes) to collector: 10.191.19.35:8003
process collector LOGON_ACK
Collector asks to keepalive: 10.191.19.35:8003
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.