Created on
04-11-2022
02:48 PM
Edited on
02-25-2025
02:04 AM
By
Anthony_E
Description | This article describes how the FSSO Collector Agent performs name resolution of the workstation as a part of forming the logon event. |
Scope | FSSO Collector Agent. |
Solution |
If the collector Agent gets the username and workstation name ( either from the DC agent or security event log ), as a part of forming the fsso logon for the given user, the FSSO collector agent has to resolve the workstation name to get the current IP address of the workstation from which the user is logged in.
The FSSO name resolution logic works in this order:
Example:
04/04/2022 15:28:10 [ 3708] DnsQuery() failed for JSMITH.test.lab, error code:9501
OS might resolve the name using one of these possible ways:
Example:
04/04/2022 15:28:10 [ 3708] resolve_ip_internal: dns look up failed, call gethostbyname():JSMITH.test.lab
FSSO Collector agent does not have any control nor can influence the name resolution in that case. If this step also fails, move to step 4.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.