Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hyder
New Contributor

FSSO Collector Agent Working Partially – AD Groups Sync Inconsistent and Firewall Policy Usage Doubt

  • I have the FSSO Collector Agent installed on the AD server, using local polling (no DC Agent).

  • The Collector Agent service is running, and user logons are being fetched correctly.

  • However, in FortiGate, the FSSO connectors status shows as "Down", yet some AD groups are still fetched (e.g 1 and 7 groups).

  • Previously, when using local FSSO user group source, FortiGate fetched 65 groups, even while status showed disconnected.

  • Now, using Collector Agent method, only 7 and 1 groups are fetched from two external connectors pointing to the same AD IP and the policies using User group type FSSO did not get affected on changing the FSSO source group from local to Collector agent.

  • I’m confused about:

    1. How group fetching is working when the connection shows -Down.

    2. Whether it’s mandatory to create FortiGate User Groups and assign AD groups to them for policy use — or can we directly use AD groups in policy source?

    3. What causes this group fetching inconsistency and disconnection status, and how can I resolve it?

Can you help clarify these behaviors and recommend the proper setup?

4 REPLIES 4
rbraha
Staff
Staff

Hi @hyder 

If connection shows down with external connector you will not be able to poll any group from collector agent, regarding this status down it may be many reasons, please check the guide below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Common-reasons-FSSO-status-shows-as-down-o...

 

You can create an user group as FSSO type and assign the correct group imported from collector agent  then specify this user group in firewall policy.

hyder
New Contributor

Hi support,

 

Customer had collector agent installed but in FGT config they chose Local as user source group (LDAP). how does this change the concept and still user creating user groups with FSSO type and adding the groups pulled locally how?

rbraha

Hi @hyder 

It's suggested that user groups to be collected on FGT from collector agent ,instead of FGT pulling locally through ldap server ,which will cause more load/ resources to poll this info.

 

hyder
New Contributor

Dear support,

The customer was using LDAP as the user source in the External Connector (FSSO), mapping LDAP groups into local user groups, which were then applied in policies. If they switch the user source from LDAP to Collector Agent, would it affect the policies...???

, as the Collector Agent is currently retrieving only 10% of the users compared to LDAP. Additionally, the External Connector status has been showing as disconnected from the beginning. Despite this, their setup continues to function, likely due to continued reliance on LDAP for group mapping.

 

regards,

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors