FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dgough
Staff
Staff
Article Id 343864
Description This article describes how FSSO detects logged-off users.
Scope FortiGate.
Solution

User removal from FSSO is managed through a workstation check and a dead entry timer. In other words, it will not read Windows Logoff Events.

 

Agent.JPG


The Collector Agent (CA) runs the workstation check in batches and the time interval between the end of one batch and the initialization of another one is specified in the Workstation verify interval field (default is 5).

 

By default, the CA utilizes WMI to retrieve the username of the currently logged-in user. If the communication is completed successfully and the username matches with the CA’s database, the entry is retained.

 

If the username is different or no user is logged in, the FSSO entry is removed from the CA and consequently from the FortiGate.

 

If the workstation check fails (due to being disabled, the PC being off or offline, or potential WMI permission issues), the dead entry timer begins.

 

The user’s FSSO session will be cleared once the timer reaches zero (default is 8 hours). The timer resets with each successful workstation check or when the same user logs on again from the same PC/IP.

 

Related articles:

Technical Tip: Explanation of FSSO timers
Troubleshooting Tip: User status 'Not Verified' on the FSSO Collector Agent
Contributors