Dear Experts,
May I know what is the different between FSSO DCAgent_Setup_5.0.0264.exe and FSSO_Setup_5.0.0264.exe ,I have One domain controller server and I want just simply install the FSSO on int DC and pull the users from there ,which file should I install?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
use FSSO_Setup file as it is so called Collector Agent, which (if you choose DCAgent mode) will spawn DCAgent installation as well as it is included in this package.
The FSSO DCAgent_Setup is the standalone installer for DCAgent only. This is helpful if you would like to (re)install DCAgent on some DC manually and not via Collector Agent.
Basically you need at least one Collector completing data about users and workstations and pushing those aggregated data (FSSO user list) into connected FortiGate unit(s). You can run Collector in multiple modes, one of them is DCAgent mode and in this case you'll need to install DCAgent part/component onto every DC in the domain and point them to Collector so they'll know where to report spotted user logons.
Best regards,
Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi Tomas,
Great, So We I have to install the collector Agent (FSSO Setup file) even I have one DC ,right ?
Thanks
Hi,
if you are not going to poll DC directly from FortiGate.
If you do not have FortiAuthenticator as collector agent.
Then you need to install at least one Collector Agent somewhere in domain.
Preferably on DC, and under Domain Admins group member account (do not need to be Administrator direcly, Domain Admins member user account made specifically for the FSSO use is OK).
Best regards,
Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Please Tomas, When you upgrade your firewall 5.6.0 to 5.6.3 ; Are you forced to reinstall the fsso client on the AD?
I have a probleme with fsso session because After upgrade to 5.6.3, no fsso session is monitor on the fortigate
That should not be needed.
It makes no sense to reinstall AD FSSO components (unless you migrate from FortiOS 4x to 5.x and so from FSSO 4.x to 5.x which happend quite a while ago).
I'd suggest to set Collector to debug log level and check the log.
Also on FGT 'diag debug auth fsso server-status' .. if it's connecting then there is either broken password for auth between FGT and Collector or something else broken more deeply (then open a ticket of FTNT support to check).
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.