Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FlavioB
New Contributor III

FSSO and logon/logoff events

Hello everybody. I' ve managed to set up FSSO in an environment like this: 2 sites, HQ and RS. Each site has 2 ADs, but on the same domain (RS " syncs" against HQ ADs). On each site, I' ve installed FSSO Agent on both ADs. On FGT60C I' ve set up LDAP to point to one local AD per site. What gets me to arise some questions, are following things. On HQ I see lots of " FSSO-logon" events but almost no " FSSO-logoff" ones, whereas on RS I see a good balance of these events. What would that mean? On HQ I see the origin IP of the " FSSO-logon" events always to be either one of the 2 ADs, whereas on RS I see client PCs IP addresses. On HQ I see always user ADMINISTRATOR logging on from one AD server. Has anybody some clues about why those things are happening? Or am I erroneously expecting something which can' t happen? And at last: is my setup correct, or did I miss or misconfigure something? Thanks in advance and kind regards. F.
0 REPLIES 0
Labels
Top Kudoed Authors