Description | This article describes how to troubleshoot port blocks in Windows Server in FSSO solutions without installing any software. |
Scope | FortiGate, FSSO, Windows Server. |
Solution |
When troubleshooting a communication issue between a DC Agent and other agents or FortiGates, and there are no permissions to install any software, it might be useful to enable logging in Windows Firewall.
FSSO collector agent uses port 8000 to communicate with FortiGate. On FortiGate's side, it is possible to run a sniffer to capture traffic that has port 8000 as the destination:
diagnose sniffer capture any 'port 8000' 4
If packets go from FortiGate to LDAP or DC server and there is no answer, it might suggest an issue on the other side.
If after double checking the configuration, there is still a communication issue and it is not possible to install software in Windows Server, it is possible to enable windows firewall logs to confirm if packets are being blocked.
To open Windows Firewall, select the Windows button, type firewall, and select Windows Defender Firewall with Advanced Security. It is also possible to press windows+r to open a Run window, type WF.msc and press Enter.
Once in the Firewall interface, follow these steps:
It will be then possible to easily verify if Windows Firewall is blocking any packet related to FSSO without installing an additional software or tool. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.