I am facing a problem with FSSO user verified but the internet is not working.
I have FSSO agent installed on DC, Status is running and perfect.
I have FSSO Fabric Connector up and running.
I have FSSO Login Logs from Users.
I have FSSO IPV4 Policy to route the AD Group working.
FSSO configure in DC agent mode at AD server and we have multiple ADCs.
Please help.
Is the internet working from same user machine when you disable FSSO ? This will help to isolate the issue if it is related to FSSO or some other config/connectivity.
Hey @yuviraj911,
reproduce the issue and find out from where user was sourced: LDAP, FSSO or maybe there is a firewall policy without user identification, which matches to your user's traffic.
- Shows firewall userlist
# diag firewall auth list | grep -i -A6 -B2 <username>
* Pay attention to source of groupping.
Shows fsso user list
# diag debug authd fsso list | grep -i -A6 -B2 <username>
* Just to verify if user in FSSO user list.
This might be due to mismatching settings on the Fortigate and FSSO collector.
Can you please:
1. Make a screenshot of the fsso connector settings on the Fortigate
2. On the Collector Agent (CA) open the Fortinet Single Sign On Agent Configuration console and click the "Set Directory Access Information" button.
If the directory access mode is "Standard", then the User Group source on the FSSO connector has to be configured as "Collector Agent"
if the directory access mode is "Advanced" , then the User Group source on FSSO connector has to be configured as "Local"
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-switch-FSSO-operation-
mode-from-Standard/ta-p/194343
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.