Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
alessandrofiumano
New Contributor

FSSO agent in hybrid AD enviroment

Hi, we have two DC onprem and two on Azure, installed agents 5.0.0314 on all four, created a network rule on azure firewall to allow all traffic (* ports and * protocols) between Fortigate appliance and all the DC (windows server 2019) (we have also a VPN from prem toward azure subnets), well, when it's time to switch connection between the DC's  agents only the two onprem talk with the appliance no traffic coming to the appliance from the two DC on azure, tried to telnet in every direction on 8000 and it shows me the service listening... any hint? thanks.

3 REPLIES 3
Dhruvin_patel

Hello!

 

Is this a DC agent-based FSSO setup? If so, which DC is the Collector Agent (FSSO agent) installed?

 

The DC Agent and the Collector Agent communicate over UDP port 8002.

 

Please ensure that communication is allowed between the DC running the DC Agent and the DC running the Collector Agent over UDP port 8002.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-Collector-agent-redundancy-with-two-W...

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Port-blocks-in-Windows-Server-in-FSS...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Common-reasons-FSSO-status-shows-as-down-o...

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-cannot-connect-to-FSSO-Age...

 

Best Regards!

Dhruvin Patel

Dhruvin Patel
alessandrofiumano

TY for the answer, the agent is installed on all 4 DCs the problem appliance can't switch on the two on azure. Will try to find something to check udp port since telnet isn't. 

GSI

Hi Alessandro,
Did you manage to solve the problem? we are facing an almost identical situation...

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors