Hi
Please go through the below link for your reference.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-Agent-in-polling-mode/ta-p/228136
Hello @Dry
On the FortiGate Go to Security Fabric > External Connectors, create a new FSSO Agent on Windows AD connector, and add the Collector Agent's IP and password.
Install it on a workgroup server and configure it to communicate with FortiGate. Enable polling mode to retrieve logon events from domain controllers.
Make sure they are reachable from the Collector Agent. Open required ports (TCP/445, TCP/135, TCP/139, UDP/137) for communication.
Please refer below article for reference on FSSO Agent in polling mode
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-Agent-in-polling-mode/ta-p/228136
Thanks,
Pavan
> FSSO Collector agent inistalled in a workgroup server
For full, proper, functionality the Collector agent absolutely must be installed on a server that it domain-joined to the domain that is to be monitored.
If the Collector is not a member of the polled domain, it will have wide consequences to what is possible:
Strongly not recommended.
will agent mode solve those issue ?
It will solve some issues, but not many.
Essentially:
- New logins can be received from DC agent and will maybe be fine
-> Collector Agent will have to do DNS lookups for workstations
-> if Collector agent is not in the domain, it must be manually pointed to correct DNS servers, and configured with DNS suffixes to check
-> workstation checks (verifying if a user is still logged in) will be impossible
It will certainly require a lot of custom configuration on Collector Agent, and the installation itself may run into issues. Like pminarik, I would not recommend such a setup.
Cheers,
Deborah
Hi,
If not looking to install FSSO agent in the server, follow the below link for your reference.
https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/888827/poll-active-directory...
If want to install FSSO agent but not DC agent, follow the below link for your reference.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-Agent-in-polling-mode/ta-p/228136
Usually it is suggested to use agent based i.e. with FSSO agent.
Regarding polling mode or DC agent mode, it basically depends on the network. If it is large network setup with lot number of users, then agent based is recommended.
User | Count |
---|---|
2588 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.