Created on 09-29-2021 04:59 AM Edited on 10-30-2024 12:26 AM By Anthony_E
Description
This article describes that the FSSO collector agent by default tries to detect workstation IP address changes by resolving the workstation host names via DNS.
The interval in which the IP address verification occurs is configured by the 'IP address change verify interval' timer shown in the below screenshot.
Solution
To mitigate this issue, FSSO collector agent v5.0.0301 and newer (released with FortiOS 6.4.7+ and 7.0.1+) adds multi-threading support for DNS resolution.
This option can be enabled under FSSO Collector Agent -> Advanced Settings -> General tab -> DNS lookup thread count.
By default, this option is set to '0' and only 1 worker/thread will be used.
However, if for example, the DNS lookup thread count is set to '10', the workstation hostname queue will be split into 10 smaller queues and each will be processed by a separate worker. The DNS lookup thread counts maximum value is 200.
This can achieve up to 10x faster processing of the Workstation IP verification queue.
Note.
It is necessary to use different amounts of DNS lookup threads for different environments.
This will mostly depend on the workstation count, DNS server response time, network delay, etc.
Screenshot for reference:
Related articles:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.