Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Manubz
New Contributor

Disconnecting after rdp

Hi, I have an unknown problem with our fortigate infrastructure. We have 2 servers (Domain controler and DNS server) with FSSO agent installed for ntlm authentication and filtering. All runs fine but we have a problem. When i open my session on our Windows domain, I can go on the Internet without any problems, all filters are running fine. But when I connect to a server using RDP protocol and when I return on the web on my computer, I don' t have access anymore. I have checked the FSSO logs but I dont have see anything in this :/ I think that it is a dns problem but I can' t identify it :/ When this problem appears, I just have to enable our ISA proxy (permanently disabled) in my web browser, check a website and disable ISA, then all runs fine again. Thank for your reply, and sorry for my french english :)
7 REPLIES 7
rwpatterson
Valued Contributor III

It is bad form to post the same question in multiple areas. This is a user supported forum. Someone (like me) will respond when they are availabile with an answer. Check your post under ' Routing and Transparent Mode' for my reply.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Manubz
New Contributor

Hi, Sorry for mutli-post, I just saw this category after my first post, I close the first and we continue here ?
Manubz
New Contributor

I believe that when you connect to another system using RDP, FSSO/FSAE will transfer your connection to that server. When you disconnect from the remote server, it leaves you in a disconnected state. Check yourself. When you connect to and after you return from the remote station, check the FGT for your login status.
 
 From the GUI it' s ' User > Monitor > Firewall' . 
rwpatterson, i copy/paster your answer here. So I have check what you said and you are right. When I take my session, I am logged in the FW right, when I connect to RDP server I' m not connected yet. Is it possible to stay open permanently the FSSO connection ? Thanks for you reply !
rwpatterson
Valued Contributor III

I am not sure as I have never tried (or wanted) to do that. You will have to check the settings in the collector to see if there is a way to do what you wish.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Manubz
New Contributor

I dit not find anything about this. It' s very bothering, everytime we connect to a server by rdp we must add and remove the proxy, it' s not fun :\
Jeff_the_Network_Guy
New Contributor III

I am trying to work through the same challenge while setting up our new Fortigate 300C. At first I was worried about allowing users to use the firewall because I kept getting disconnected. Then I realized that the Fortigate is picking up my connections to servers, and then disconnecting me when I log off the server I was working on. As a temporary work around, I' ve taken to creating host object for Network Admin workstations since I' m always bouncing in and out of servers all day. I feel like I' m going to have to open a ticket with Fortinet for this one.
----------------(-- Jeff
----------------(-- Jeff
Jeff_the_Network_Guy
New Contributor III

Depending on how you connect to the server via RDP, one possible workaround is to ignore the server credentials. This is assuming that the following is occurring: If I sign onto my PC in the morning as my normal User account, but then connect via RDP to a server as my Admin account, then I should be able to tell the collector agent to ignore logins for my Admin account. That way my RDP sessions would be ignored by FSSO. Assuming I do not have machines authenticating to the firewall as my Admin account then this should be a viable option.
----------------(-- Jeff
----------------(-- Jeff
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors