Created on 04-01-2015 10:16 AM Edited on 11-24-2024 11:32 PM By Jean-Philippe_P
Description
This article discusses Windows event IDs used by FSSO in WinSec polling mode.
Scope
FortiAuthenticator.
Solution
* Some Event IDs are not supported alone and they required another event to correlate the login information.
For example:
** By default the Collector Agent is using a subset of events. Which event IDs are monitored is configurable with 'Windows Security Event ID to poll' under Advanced settings:
2. FortiGate (FGT) has an integrated poller as well. Its local polling mode also uses the Windows Security Event logs, however, currently the supported event subset is smaller.
Hint:
If the FortiGate poller debug log shows 'no domain from <IP>' then 'default-domain' should be set in the 'config user fsso-polling' configuration to avoid this failure.
3. FortiAuthenticator supports the following event IDs:
* Support for these events is available by enabling under the Fortinet Single Sign-On (FSSO) section -> SSO -> General -> Enable Windows event log polling (e.g. domain controllers/Exchange servers) [Configure Events].
Note that if there is no Event in the Windows Security Event log, FSSO cannot pick the users/machines up either.
If the events IDs are not generated likely an auditing group policy is prohibiting this.
Related Articles:
Technical Tip: FSSO local poller (FSSOD) limitations compared to FSSO collector agent.
Technical Tip: FSSO choose between DC Agent mode or Polling mode
Technical Tip: Downloading FSSO agent software
Technical Tip: How to validate MD5 checksum hash for FSSO installer
Technical Tip: How to install FSSO Collector Agent
Technical Tip: Comparison between DC-Agent mode and polling mode
Troubleshooting Tip: FSSO Complete troubleshooting for TAC tickets
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.