Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ICT_Middelkerke
New Contributor

FSSO problem afther domain migration

Hi

We recently migrated our 2 Windows 2008 R2 domain controllers to Windows 2012 R2.

Ather the migration we installed FSSO version 4.3.0151 on the 2 new controllers given this is the version in the online download folder for our current Firmware version (5.0 build 271) for our 100D FW.

 

I copied all the settings from our old domain controllers FSSO config (manualy) that was the same version of FSSO by the way. The "Group Filter" settings showed two record that had "Filter set by FortiGate (do not edit)" so i figured our FW set these settings.

 

I am however unable to make our Fortigate update these settings.

I've tried recreating the rule under Authentication=> Single Sign-on, no effect

Tried to create a new SSO rule, no effect

Reconfigured the LDAP connection, was testing fine given that we reused the IP-addresses and hostnames from our old domain controllers.

 

I tried adding the Group Filter settings manually, no effect and i even tried  FSSO agent version 5.0.0239 also no effect.

 

Our users are complaining about the login screen they now receive when browsing.

 

Is there something i can try ?

 

Update : We are not using polling mode but Single Sign on Agent mode

 

2 REPLIES 2
boneyard
Valued Contributor

im not 100% sure how this works on 5.0, you might also look into upgrading to 5.2, also because of the recently discovered ssh backdoor.

 

but in 5.2 that automatic filter is done based on the LDAP server settings.

 

on CLI the config user adgrp command has an effect, you could check those out.

 

also that filter style has to match if you use simple or advanced mode on the FSSO collector agent.

 

but what you don't totally explain is that if it is just the filter that bothers you or if FSSO fails completely. do you see any logon user in the fsso agent? have you tried to reinstalling the thing and not import settings, but redo them manually?

xsilver_FTNT
Staff
Staff

Hello,

 

I'd suggest to :

- use later FSSO firmware, as 4.3.0151 was released with FortiOS 5.0.7 then it's a bit old, and B0151 had an issue in long term run on some DCs. ColelctorAgent process was crashing.

- when FortiGate has FSSO Agent equipped with LDAP server, that LDAP is used to read groups from AD and then selected ones are pushed by FortiGate to Collector as per-FGT-SN Group Filter (those "do not edit" ones). But LDAP in Agent makes FortiGate use LDAP style of Group Filter, while Collector default mode of operation is Standard which does use MS format DOAMIN/GROUP .. navigate to Collector / Set Directory Access Information .. and there switch from Standard (most probably used) to Advanced mode (which uses LDAP formats).

 

Kind regards, Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors