Description
This article describes the two modes of retrieving user information from domain controllers for FSSO that are available on the FSSO collector agent.
When configuring FSSO as agentless, in that case, the FortiGate provides polling from the domain controllers (shown in FortiGate GUI under External Connectors as 'Active Directory Connector').
DC-Agent mode is available only from the Collector Agent or FortiAuthenticator.
Scope
FortiGate, FortiProxy.
Solution
DC-Agent mode.
In DC Agent mode, a Fortinet authentication agent is installed on each domain controller.
These DC agents monitor user logon events and send the information to the collector agent, which stores the information and sends it to the FortiGate.
The DC Agent installed on the domain controllers is not a service like the Collector agent — it is a DLL file called 'dcagent.dll' and is installed in the Windows\system32 directory.
This enables the DC-Agent to directly read authentication events from the Local Security Authority Subsystem Service (LSASS).
DC Agent mode provides reliable user login information, however, installing a DC agent on every domain controller is necessary.
A reboot is needed after the agent is installed. Each installation requires some maintenance as well. For these reasons, it may not be possible to use the DC Agent mode.
Each domain controller connection needs a minimum guaranteed 64 kbps bandwidth to ensure proper FSSO functionality.
Configure traffic shapers on the FortiGate to ensure this minimum bandwidth is guaranteed for the domain controller connections.
Polling Mode.
Having a DC-Agent installed on every domain controller can ensure the maximum accuracy for detecting user logon.
However, some users do not want to have third-party software installed on their domain controllers.
In polling mode, there are three options: NetAPI polling, Event log polling, and Event log using WMI.
All share the advantages of being transparent and agentless.
However, when using local polling from the FortiGate directly, there is no such option, only Event Log Polling is used.
In polling mode, the Collector Agent polls port 445 of each domain controller for user login information every few seconds and forwards it to the FortiGate.
There are no DC Agents installed, so the Collector agent polls the domain controllers directly.
Related article:
Technical Tip: Windows event IDs used by FSSO in WinSec polling mode
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.