Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TrevorCampbell
New Contributor

FSSO on multiple DC' s

Hi One of our clients are in the process of upgrading from Windows 2003 to Windows 2008 R2 servers and I' m having some issues with FSSO under Windows 2008 R2. Keeping in mind this is the first time I' ve installed multiple collector agents (they only had 1 DC before), and am aware that version mis-matches may be part of the issue. I' m planning to fix that tonight, but would like to clarify before I upgrade the old FSAE to FSSO Old (working) setup: FortiGate 60C - 4.0 MR2 Patch 8 Windows 2003 DC running FSAE 3.5.059 New setup: FortiGate 60C - 4.0 MR2 Patch 8 2 x Windows 2008 DC' s running FSSO 4.0.0108 (Windows firewall is disabled at present) Windows 2003 DC running FSAE 3.5.059 (still running) On the FortiGate I' ve setup the " FSAE Collector IP" with all three servers - with the Windows 2008 servers first and the old Windows 2003 server last. The Collector agent on both 2008 servers are set to monitor the DC Agent on both 2008 servers (due to version mis-matches they don' t monitor the 2003 server). The 2003 server is only monitoring itself. When I run FSAE / FSSO on the servers and click on " Show Service Status" I don' t see the FortiGate listed on either Windows 2008 server, but do see it listed on the Windows 2003 server. If I look under " Set Group Filters" - all three servers show the same thing - ie: the FortiGate and the groups. If I upgrade FSAE 3.5.059 on the Windows 2003 server to 4.3.0108 I presume I can get the Collector Agent on all of the DC' s to montor all of the DC' s. When I do that should I then see the FortiGate listed on all three DC' s under " Show Service status" ? OR Will it only show on the server that the FortiGate is actively using ? If it' s only the server the FortiGate is actively using - is there any reason why it' s connecting to the Windows 2003 box at the moment given this is the last of three servers listed on the FortiGate under Directory Services ? Thanks in advance.
Trevor
Trevor
2 REPLIES 2
jmac
New Contributor

The FortiGate only communicates with one Collector Agent at a time; other configured collector agents are effectively on " standby" if the FortiGate loses communication with the active unit. If you have multiple collector agents configured, you must designate their IPs and passwords in the Directory Service configuration for the domain in the User/Directory Service section of the FortiGate (note: do not create multiple Directory Service entries, add multiple IPs to a single DS entry). If you want to test if the FortiGate communicates with another Collector Agent, stop the " Fortinet Single Sign On Agent Service" on the server with the active connection and see if one of the other servers gets the connection. Only one server is required to run the collector agent; you can optionally install it on one or more additional servers for redundancy. However, if you are using the DC agent then all DCs must have it installed and each collector agent must be configured to connect to all DCs to collect data. If the collector agent on the 2008 DC does not monitor the 2003 DC, then any logins authenticated against the 2003 DC will not be collected and reported to the FortiGate. You must perform the DC agent install to all DCs from each collector agent upon initial setup so it will establish the appropriate links for monitoring. Also, the DC agent needs to be upgraded on the 2003 server. You can do so by adding it as a DC to monitor from the collector agents running on the 2008 servers, which will then update the agent (but require a restart of the DC). If you need to upgrade the DC agent to a newer version (the current version number shows in the " Show Monitored DCs" window), then from the " Select DC to monitor" , uncheck the DC with the older version & click OK (do not restart the DC), then re-check the DC and click OK. Restart the DC after both steps are complete to use the updated version. Once you test communication between the FortiGate and collector agent running on 2008, I would remove the collector agent from the 2003 server and make sure the DC agent is updated on 2003 and monitored by the remaining collector agents.
TrevorCampbell

Thanks for clarifing that for me JMAC. I have scheduled to upgrade the agent on the 2003 box over the weekend so will do the testing as you suggest prior to doing this. I did add all of the server IP' s to the one Users / Directory service section on the FG and had the 2008 boxes listed first. Perhaps the issue is the FG was already talking to the 2003 box and the 2008 servers initially had their firewalls enabled, so that would explain why it is connecting to the 2003 server. I' ll post back if I still don' t have any luck with this. Cheers
Trevor
Trevor
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors