Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Travisffs
New Contributor

FSSO is polling wrong information from DC:s

Hi,   I have some problems with the newer version of FSSO is polling wrong data from DCs. We have mixed Windows Server 2008 R2 and Windows Server 2016 DC: s in our environment. We're using event log polling of DC: s, we have right now 50+ DC:s.

 

The main problem is that data that is being polled with FSSO 5.0.0264 state that the user has the workstation of the DC that is being polled. So the update can start with the DHCP server, then DC and a few hours later it finally get the correct workstation bound to get correct user.   Server1: FSEA 3.5.059 Server2: FSSO 5.0.0264   The polling with FSEA 3.5.059 works fine and no problems, but as soon as we switch to server2 and FSSO 5.0.0264 we are facing problems in the morning with users not able to reach Internet due to they are seen as guest users due to wrong information polled.   I guess the entry in the log named [UPDATE_LOGON_LIST] is the data sent to Fortigate? That sting often contains the DC it made the event log polling on.   [RECV_EVENT_FROM_DC]  packet_len:XX dcagent_ip:DC_IP time:XXXXXXXXXX data_len:XX data:DC_HOSTNAME/DOMAIN/USER ip:0.0.0.0 [UPDATE_LOGON_LIST]   action:update_entry workstation:DC_HOSTNAME ip:DC_IP:0.0.0.0 user:DOMAIN\USER   Something that we see a lot is also that FSEA 3.5.059 is listing about 500 users more than FSSO 5.0.0264.   We have had the same problem in both 4.X.X and other 5.X.X versions.   Any ideas what might be the issue?

Why do FSSO see a user authenticating with the DC as its workstation, which it is not...

0 REPLIES 0
Labels
Top Kudoed Authors