Hi,
I have some problems with the newer version of FSSO is polling wrong data from DCs.
We have mixed Windows Server 2008 and Windows Server 2016 DC:s in our environment.
We're using event log polling of DC:s.
Server1: FSEA 3.5.059
Server2: FSSO 5.0.0264
The polling with FSEA 3.5.059 works fine and no problems, but as soon as we switch to server2 and FSSO 5.0.0264 we are facing problems in the morning with users not able to reach Internet due to they are seen as guest users.
I guess the entry in the log named [UPDATE_LOGON_LIST] is the data sent to Fortigate?
That sting often contains the DC it made the eventlog polling on.
[RECV_EVENT_FROM_DC] packet_len:XX dcagent_ip:DC_IP time:XXXXXXXXXX data_len:XX data:DC_HOSTNAME/DOMAIN/USER ip:0.0.0.0 [UPDATE_LOGON_LIST] action:update_entry workstation:DC_HOSTNAME ip:DC_IP:0.0.0.0 user:DOMAIN\USER
Something that we see alot is also that FSEA 3.5.059 is listing about 500 users more than FSSO 5.0.0264.
We have had the same problem in both 4.X.X and other 5.X.X versions.
Any ideas what might be the issue?
User | Count |
---|---|
2675 | |
1410 | |
810 | |
702 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.