Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Saad_Mirza
New Contributor

(FSSO) Multi ad logins with the single IP

Current Setup:

We are using Explicit Proxy on FortiGate with FSSO-based user authentication.

Challenges Faced:

Scenario 1:

We are using N-Computing devices, where multiple users log in simultaneously. These users all share the same IP address.
As a result, we are facing the following issues:

  • Some users are intermittently unable to access the internet.

  • In certain cases, user traffic is incorrectly attributed, leading to policy enforcement mismatches and access issues.

Scenario 2:

We have scenarios where a single user account is logged in on multiple devices simultaneously.
This allows the user to access the internet from multiple devices at the same time, which is affecting the reliability and accuracy of user-based controls.

 

Is there any solution to over come the above issue.

3 REPLIES 3
funkylicious
SuperUser
SuperUser

TS Agent i think would resolve your issue with multiple users using the same ip, https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-setup-TS-Agent-configuration/ta-p/1... 

"jack of all trades, master of none"
"jack of all trades, master of none"
hst1
Staff
Staff

Hello Team,

Pleas do refer the below document 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-setup-TS-Agent-configuration/ta-p/1...

 

IN addition to this do check your DNS logs and confirm that the DNS is getting updated., cached DNS entry could also cause this issue.

 

regards 

filiaks1
Contributor II

Also have not tested this but learning from XFF header the real ip could be useful in your case.

 

How to learn Client-IP from X-Forwarded-F... - Fortinet Community

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors