Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jond
New Contributor III

RSSO and user groups

Hi there,

 

Am I imagining it or can RSSO be a little intermittent?  I'm in a very busy site but a small proportion of my users are not showing with RSSO group filled.  No particular reason so far as I can see.  It's picking up the usernames but not the groups.

 

Any idea of how I can make it more reliable?

Cheers

Jon

1 REPLY 1
xsilver_FTNT
Staff
Staff

Hi,

I would start with checking which users are getting in without group.

And sniff the RADIUS accounting (def.port 1813) to see if expected group membership bearing attribute has something actually set inside. Default group attribute is Class AVP, but it is configurable via 'set sso-attribute' under 'config user radius' object.

Then, what's your unit, FortiOS and accounting traffic rate, roughly ?

 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Labels
Top Kudoed Authors