jfelix09
Staff
Created on
08-22-2024
10:32 AM
Edited on
08-23-2024
12:45 AM
By
Jean-Philippe_P
Article Id
335611
Description | This article describes how to secure the connection between a TS-Agent and an FSSO-Collector Agent (Windows and FortiAuthenticator). |
Scope | TS-Agent and FSSO Collector Agent, FortiGate, FortiAnalyzer. |
Solution |
This article describes how to secure the connection between the FSSO TS-Agent and the FSSO Collector Agent.
The FSSO TS-Agent will authenticate against the Collector Agent using TLS with a pre-shared key (PSK).
This PSK should be known by both client (FSSO TS-Agent) and server (Collector Agent).
In the FSSO-CA configurator tool, check the 'Enable SSL' box and set the 'preshared key'.
It is also possible to configure the SSL port (by default, FSSO-CA will be listening on TCP/8003).
After, select 'Apply' to save the configuration.
In the FSSO TS-Agent configurator tool, select the FSSO CA IP address and port, check the 'Secure connection' box, and set the same pre-shared key used in the FSSO CA configurator tool. Select 'Apply' to save the settings.
If keepalive messages or login information are not showing under the FSSO Collector Agent -> Show Monitored DCs, it may indicate that the TCP or TLS handshake didn't happen correctly.
|
Labels: