Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
romanr
Valued Contributor

FASE not working properly

Hi, I have some FSAE installations and all of them but one work fine! This one installation causes me weird troubles and maybe someone could give me a hint to get further with it: Windows 2008 AD, FSAE installed on the DCs (Both 64Bit). Fortigate 620B, 4.0 Mr1, Patch 1 (Upgrade to Patch 2 will happen next week!) diag sys authd fsae list -> shows only about 50blogged in users, which is only abourt 20% of the number it should be! the same under User -> Monitor .... I will see about 80-90% " guest" user entries... And these people will then only have the guest access rights??? As mentioned on the top of the posting, there is from my point of view nothing special in the installation then with other FSAE installation at my customers I have got, where it just works normal.... Anybody got a clue where to dig further before opening a support ticket with fortinat TAC? cheers, Roman
8 REPLIES 8
rwpatterson
Valued Contributor III

Some obvious questions... [ul]
  • What' s different here than other installs? DC OS? FSAE version? FortiOS version? DHCP vs hard coded addresses?
  • Can you spot any differences between a working PC and a non working? [/ul] One clue: If using hard coded addresses, DHCP still needs to enabled on the work stations. (ask me how I know.... [:' (])
  • Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    romanr
    Valued Contributor

    Hi Bob, the only real difference might be the 2008 64Bit DC, on the other working installations we have everywhere 2003! But log output from the FSAE totally looks the same, so I cannot really just put it on to the DC OS.... Workstations come all from the same SCCM (Microsoft System Center Configuration!) installation and are all XP systems! So there should not be a difference.... In this installation everything is handled via DHCP and direct reservations, so all workstations have dhcp-addresses. FortiOS and FSAE versions are the same as other working installations... Hm... I' ll dig further... cheers.roman
    discoveryit
    New Contributor

    i had this happen to me.. did you install the client on each server or push the client to the other DC from the installer of the first server?... i had to physically install the client on all my DC' s because the first install did not properly install on the other DC' s from the " primary" dc. I installed on both servers then Synced the settings between them.. worked like a charm after that.. also make sure that your policy is right in the FSAE to log " Domain Users" or the Specific users you need...
    FCNSP
    FCNSP
    romanr
    Valued Contributor

    I think we found the cause of the problem... Seems to be the Microsoft SCCM infrastructure, that is doing administrative logons from the clients.... Those administrative users are not monitored or in any groups and this seems to interfere with FSAE!!! We will do a further investigation and hand the results over to Fortinet..... cheers, Roman
    rwpatterson
    Valued Contributor III

    Can these logins be ignored from FSAE? May be a quick solution.

    Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    romanr
    Valued Contributor

    Can these logins be ignored from FSAE? May be a quick solution.
    Hi Bob, had the same thought and disabled it after I saw that... Will have the proper answers tomorrow morning, after all users are logging back in :)! I will have a guy with me tomorrow with SCCM and more detailed MSAD know how then me... So I' ll not dig further today! cheers.roman
    romanr
    Valued Contributor

    Ignoring the administrative users at the FSAE agent did the job! cheers
    rwpatterson
    Valued Contributor III

    Sweet.

    Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    Labels
    Top Kudoed Authors