Is it really necessary to have a 2nd FSSO agent on the fortigate as colllector agent?
i am trying to setup a 2nd AD as FSSO agent.
what will happens if the main FSSO agent server is rebooted or went down?
It depends on your needs. If the main agent is going down, Fortigate collects data from the second agent. If you don't have a second agent, Fortigate doesn't know who logged in recently. Because of that, new logged-in users can't access resources that are processed with FSSO rules. Also, Users who are already logged in can continue to access resources until the cache expires.
For more details, please have a look to the KB article below. I would also remark both FSSO CAs should be synced with polling hosts, group filters, and ignore user lists:
Hello,
Thank you for posting your query on support portal.
When both the Primary and Secondary FSSO Collector Agents are set up in the FortiGate firewall, the firewall initially connects to the primary Collector Agent.
In the event of the primary Collector Agent failing, the firewall switches to the secondary Collector Agent for continued operation.
For more information please refer the below article:
REF: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-Collector-Agent-failover-behavior/ta-...
Regards,
Piyush
User | Count |
---|---|
1922 | |
1144 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.