I have one 200D (on 5.4.10), FSSO seems work well, but Collector Agent keeps logging following message:
"error parsing file header:C:\Program Files (x86)\Fortinet\FSAE\TSAgentSyncID.dat"
Is there something I should worry about?
I have installed both Collector Agent and DC Agent on two DCs (Win2012 R2) under Domain\Administator account. I have set full control permission to "Authenticate User" toward Fortinet folders and registries.
Thanks a lot.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
looks like permission issue.
Try to run Collector Agent service under Domain Admins group member account to test it.
If you do run service under restricted account, then make sure that account has full privilege on FSAE folders and registry keys (including sub-tree and folders).
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Thank you for your reply.
This is weird. The Fortinet Single Sign On Agent Service is running under the Domain\Administrator account, which is a member of Domain Admins group. And Domain Admins,Domain Users, and even Authenticated Users have Full Control permission to the following folder and registry keys, including sub-folders and sub-tree:
C:\Program Files (x86)\Fortinet\FSAE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Fortinet\FSAE\collectoragent
C:\Program Files\Fortinet\FSAE
HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FSAE\dcagent
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.