Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Silver
New Contributor II

FSSO Issues

Dear All,

Anyone can clear me about this issues if it's normal or not.

My IT person on the same sub net with different machine using the same username to login on their machine having some issues. 

 

1) User 1 login with username test01 and User 2 login with username test01

2) Both machine on the same Lan with different IP Address User 1 192.168.1.2 and   User2 192.168.1.3

3) website example facebook.com visited by User 2 

 

Problem when generate a report its showing that user 1 with username test01 and ip address 192.168.1.2 has visited the website which he or she never visited this site. But User 2 Confirmed she has visited the website.

 

Why we are getting this type of report. Is it normal because both are using the same username or something wrong plz.

 

Thanks in advance

 

 

10 REPLIES 10
CL
New Contributor

Silver,

 

The FortiOS 5.2 Handbook FSSO general troubleshooting section does mention a similar problem to yours.  It may be useful to you, as it sounds like multiple concurrent logons by the same user on different computers is known to potentially cause some problems.  From page 496 in my copy of the handbook:

 

Users on a particular computer (IP address) can not access the network

Windows AD Domain Controller agent gets the username and workstation where the logon attempt is coming from. If there are two computers with the same IP address and the same user trying to logon, it is possible for the authentication system to become confused and believe that the user on computer_1 is actually trying to access computer_2.

 

Windows AD does not track when a user logs out. It is possible that a user logs out on one computer, and immediate logs onto a second computer while the system still believes the user is logged on the original computer. While this is allowed, information that is intended for the session on one computer may mistakenly end up going to the other computer instead. The result would look similar to a hijacked session.

 

Solutions Ensure each computer has separate IP addresses. Encourage users to logout on one machine before logging onto another machine. If multiple users have the same username, change the usernames to be unique. Shorten timeout timer to flush inactive sessions after a shorter time.

 

I know your situation is a little different because the computers do have different IPs, but other than that it sounds similar.  You probably should use unique usernames for each person at the very least.

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors