Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shaun23
New Contributor II

FSSO Morning Login Problem

Hi,

 

Just for information really - I inherited and administer an enviroment where we have two 1500Ds, 6 domain controllers and two Collector Agents installed on two of the domain controllers with everything running in DC Agent Mode.

 

Our service desk were reporting issues whereby an end user would have problems accessing the Internet first thing in the morning, and after some reading on these forums I offered a temporary fix where they would get the end user to lock and unlock their PC, regenerating a 4624 event id to be picked up by FSSO from the domain controllers to push them out on the identity based policy again.

 

My main finding after troubleshooting was that when a user would first login in the morning the local event id 4624 would be generated but it had a logon type of 11 (CachedInteractive), this pretty much meant that the users PC was not communicating with the domain and instead using cached credentials to log into the PC with, no event was seen by the domain controllers.

 

I found the following local policy: Security Settings -> Local Policies -> Security Options -> Interactive login: Number of previous logons to cache (in case domain controller is not available) and set it to '0', so the PC would never cache credentials.

 

After applying this policy, in the morning the end users are now getting a logon type 2 4624 event id and FSSO is picking it up properly. I'm not too sure if this is a true fix to the problem but hopefully this helps anyone else with FSSO morning login problems.

 

Cheers

Shaun

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors