Is there a way to exclude certain IP addresses from collecting authenticated users ?
Hi,
dieter wrote:Is there a way to exclude certain IP addresses from collecting authenticated users ?
yes
If your Collector is getting updates from some sources and you do not want those sources to collect authenticated users, then options are:
1. if in DCAgent mode simply uninstall agent from those DCs when you do not want auth info from
2. if in polling mode then remove DC from polled controllers
3. list of polled DCs is in "dc_list"="" key
4. list of connected/known DCAgents is on the end of exported config from Collector
5. you can ignore updates from certain DC via "dc_agent_ignore_ip_list"="" key
6. all the keys are in [HKEY_LOCAL_MACHINE\software\fortinet\fsae] sub-tree ..
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
dc_agent_ignore_ip_list seems to be an undocumented feature. But it seems to work.
Thank you
Curious: In the Firewall User monitor I don't see users associated to the excluded IP addresses.
In Forward traffic log however, some traffic from those IP's have a user associated...
In User even log, I see FSSO logon/logoff events on the excluded IP's. Log off event for most users us about 3 seconds after logon event. Probably enough to have some traffic related to a user...
On 5.6.2 by the way.
Hello all,
I was wondering this myself, In our case we have multiple users being associated from the Wireless Lan Controller IP
As this is Wifi Logon they before they have an IP they get associated with the WLC IP. so we wanted to exclude the WLC IP from ever being associated to any user.
Kind regards,
Peter
Hi Peter,
point 5. from my original post .. "dc_agent_ignore_ip_list"="" is the answer.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Any documentation available on how to create this dc_agent_ignore_ip_list key if I have multiple IPs?
Separated by semicolons seems to work.
Not documented afaik.
It says: Subnets are not supported, each IP address must be entered individually. This should change soon.
Best Regards,
Alivo
livo
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.