Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Grasmuis
New Contributor

FSSO Advanced with DC Agents - Is there a way to track IP changes

Hi All

 

I have a customer with Advanced FSSO and DC Agents, all seem to be working fine. Some of their users switch between LAN and WiFi without logging out of their system - picking their laptop up and walking to a different building and into a different subnet. Subsequently the FSSO loses the AD Account and IP pairing and naturally their traffic is marked as 'Guest' (valid internal IP, no authentication as source).

 

They are not using the FortiAPs.

 

What are my options in getting their browsing to work seamlessly when moving between LAN and WiFi subnets?

 

Edit: Just as an added note here, I've read other threads from years ago that refer to enabling NTLM, DNS or DHCP tweaks, etc. Are these solutions still valid? Would the FSSO software not been updated since then? Is there a more recent thread that discusses this issue?

 

Any pointers-in-the-right-directions are appreciated!

16 REPLIES 16
azhar667

As per my finding and this is the problem with FSSO to track IP change.

FSSO agent is not monitoring IP change its only check the event ID 4624 and match the IP address which requested from firewall.

In this forum this issue is still not fixed and there is no solution or workaround.

Sidewaysguy
New Contributor III

Also as a thought, is the wireless subnet defined in AD Sites and Services?

romanr
Valued Contributor

JacquesSA wrote:

 Some of their users switch between LAN and WiFi without logging out of their system - picking their laptop up and walking to a different building and into a different subnet.

Hey,

 

my 2 cents: the only way to really reliable handle this is to use the SSO Agents on the clients and the FAC which will reult in additional licensing costs...

 

 

Br,

Roman

dmcquade
New Contributor III

We've had the same issue. In our case we use FortiAuthenticator and have FortiClient installed on the workstations and laptops. We changed our configuration to add the Forticlient SSO Mobility Agent in addition to the DC Agents. Machines using FortiClient can roam freely and have their IP address update in real time thereby giving them access to all of their group specific access rules.

romanr
Valued Contributor

Hey,

 

as long as the PC does not trigger any new login event in the windows world, after the IP address change -> Then any active directory method will not know about the changed ip address. This is due to Active Directory design and the only thing Fortinet can do about it -> Is provide a client based solution, which is there via FortiAuthenticator and SSO agents...

 

If it is only for clients and web-access. Another smart solution can be using Explicit Proxy and Kerberos (or NTLM) Authentication. But this isn't an easy solution and will bring up other issues.

 

Br,

Roman

neonbit
Valued Contributor

Does your wireless vendor allow you to send RADIUS attributes? Ifso you could get it to send the user info each time a user logs into the wifi.

2pm
New Contributor

I am still experiencing this same issue when a user switch subnets. For example going from wired to wireless. There is about a 5 minute delay before our FSSO collector sees the change. From the computer, if they do a simple gpupdate, FSSO sees the change and work right away.

Labels
Top Kudoed Authors