FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Anonymous
Not applicable
Article Id 207592
Description

This article describes why Fortinet Single Sign-On (FSSO) stops working after upgrading to FSSO Collector Agent 5.0.0290.

Scope FortiGate, FSSO, Collector Agent
Solution

It has been noticed Fortinet Single Sign-On Agent service appears to be stopped, however, when trying to restart the service, it stops again shortly after.

 

If it is verified the FSSO CA debug logs,  an error 'cannot bind to UDP socket' can be found.

 

pkavin_0-1648224302059.png

 

Starting FSSO Collector Agent build 5.0.0290, the FSSO Collector Agent includes a Syslog service that runs on UDP port 514.

 

If UDP port 514 is already in use by another application/service/server on the Windows machine running the FSSO Collector Agent,  this error while running FSSO - 'cannot bind to UDP socket' can be seen.

 

To verify the same, open command prompt, run as administrator.

Enter command ‘netstat –anbo | find ":514" , this will show Active Connections along with the listening port number.

 

On FSSO Agent build 5.0.0290 and later, under Advanced Settings -> Syslog source list -> Uncheck 'Enable this feature', since it is also using port 514.

 

After disabling the FSSO Collector Agent’s Syslog functionality, the FSSO Collector Agent should start successfully.

 

pkavin_1-1648224448922.png

Contributors