I would like to ask a few questions about FSSO.
I am going to use DC agent mode.
1) If I have multiple AD servers, I should install the agent in every AD server and then create separate connectors on FW?
2) Also about the timers the config of Collector has. Is there any point on changing them according to the environment from your experience?
Thanks and regards,
Since you are having multiple AD servers, its necessary there to install only DC Agents and one Collector Agent no need to install CA in every domain, every DC Agent will send this info to CA.
Regarding second question, these are by default configuration and the below documentation it might give more info about these timers on FSSO.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.