I was looking at the forward traffic logs on our firewall and I saw one of our administrator accounts was listed as the source for a particular endpoint. The admin was not logged in, only one user was currently logged in, computer has been rebooted a number of times since I first saw this and this admin account is still linked as the source for this computer.
The source entry appears to get its information from FortiClient?
How are you doing authentication on your firewall; did the user have to authenticate before being allowed to generate traffic? Any FSSO? Is the user connected via VPN?
User | Count |
---|---|
2061 | |
1175 | |
770 | |
448 | |
343 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.