I need to install FSSO agent & DC agent in secondary DC. in primary DC FSSO client is their & sync with fortigate now we are installing DC FSSO agent on 2nd DC but we did not restart the DC its not sync with fortigate does restart is needed ? I just want to configure 2nd DC in fortigate in case primary fails. also at the time of installing collector agent we give option to select domain controller do we need to select both domain controller or only one that we installing the collector agent on. ( also user facing an issue after installing FSSO agent on 2nd Dc but haven't restart th DC system & does not sync with fortigate hence many user are losing internet access in middle on session does currently its uninstalled from secondary DC) Thanks in advance
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
Solved! Go to Solution.
Hi,
if you do have one or few domains, but all those are going to be handled by 2 Collector Agents (handling same domains) and you run this in with DCAgents, then in short:
- you might have 2 Collector Agents installed on domain member computer, DC is preferred, for resiliency
- you need to ave DCAgent installed on every DC which might be used as logon server (usually all DCs)
- you have to have those DCAgents set to report to both (all) your Collector Agents, so both collectors will have same logons from those DCAgents, no matter where those logons happen
- and finally you have those two collectors set inside a single FSSO Agent on FortiGate(s).
This is FSSO Agent setting on FGT is a list. One and only one of listed Collectors is used on FGT until connection to that collector fail. Then next in list is connected and used, till this one fail. When last on list fails, first is used again. List is cyclic. There is connection to only one "serving" collector per FGT at a time. There is no primary, or backup collector, neither master/slave. All collectors are equal and not syncing. No fallback to previous 'master' as there is no master collector. Those are standalone, independent units.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi,
if you do have one or few domains, but all those are going to be handled by 2 Collector Agents (handling same domains) and you run this in with DCAgents, then in short:
- you might have 2 Collector Agents installed on domain member computer, DC is preferred, for resiliency
- you need to ave DCAgent installed on every DC which might be used as logon server (usually all DCs)
- you have to have those DCAgents set to report to both (all) your Collector Agents, so both collectors will have same logons from those DCAgents, no matter where those logons happen
- and finally you have those two collectors set inside a single FSSO Agent on FortiGate(s).
This is FSSO Agent setting on FGT is a list. One and only one of listed Collectors is used on FGT until connection to that collector fail. Then next in list is connected and used, till this one fail. When last on list fails, first is used again. List is cyclic. There is connection to only one "serving" collector per FGT at a time. There is no primary, or backup collector, neither master/slave. All collectors are equal and not syncing. No fallback to previous 'master' as there is no master collector. Those are standalone, independent units.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi Tomas, thank you so much for so much. it help a lot to understand how fortigate FSSO works Regards Vishal Rathod
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1743 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.