Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fortiFWuser
Contributor

FSSO timers and multiple AD

Hello, 

 

I would like to ask a few questions about FSSO. 

I am going to use DC agent mode.

1) If I have multiple AD servers, I should install the agent in every AD server and then create separate connectors on FW?

2) Also about the timers the config of Collector has. Is there any point on changing them according to the environment from your experience?

image.png

Thanks and regards, 

Konstantinos

 
 

 

 

1 REPLY 1
rbraha
Staff
Staff

Hi @fortiFWuser 

Since you are having multiple AD servers, its necessary there to install only DC Agents  and one Collector Agent  no need to install CA in every domain, every DC Agent will send this info to CA.

 

Regarding second question, these are by default configuration and the below documentation it might give more info about these timers on FSSO.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Explanation-of-FSSO-timers/ta-p/189420#:~:....

 

Labels
Top Kudoed Authors