The FortiGate only communicates with one Collector Agent at a time; other configured collector agents are effectively on " standby" if the FortiGate loses communication with the active unit. If you have multiple collector agents configured, you must designate their IPs and passwords in the Directory Service configuration for the domain in the User/Directory Service section of the FortiGate (note: do not create multiple Directory Service entries, add multiple IPs to a single DS entry). If you want to test if the FortiGate communicates with another Collector Agent, stop the " Fortinet Single Sign On Agent Service" on the server with the active connection and see if one of the other servers gets the connection.
Only one server is required to run the collector agent; you can optionally install it on one or more additional servers for redundancy. However, if you are using the DC agent then all DCs must have it installed and each collector agent must be configured to connect to all DCs to collect data. If the collector agent on the 2008 DC does not monitor the 2003 DC, then any logins authenticated against the 2003 DC will not be collected and reported to the FortiGate. You must perform the DC agent install to all DCs from each collector agent upon initial setup so it will establish the appropriate links for monitoring.
Also, the DC agent needs to be upgraded on the 2003 server. You can do so by adding it as a DC to monitor from the collector agents running on the 2008 servers, which will then update the agent (but require a restart of the DC). If you need to upgrade the DC agent to a newer version (the current version number shows in the " Show Monitored DCs" window), then from the " Select DC to monitor" , uncheck the DC with the older version & click OK (do not restart the DC), then re-check the DC and click OK. Restart the DC after both steps are complete to use the updated version.
Once you test communication between the FortiGate and collector agent running on 2008, I would remove the collector agent from the 2003 server and make sure the DC agent is updated on 2003 and monitored by the remaining collector agents.