Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Reshans
New Contributor

FortiGate FSSO Issue

FortiGate FSSO has been successfully configured and enrolled. However, when applying it to a firewall policy and checking user connectivity, the connection appears to be successful.

The issue arises when a user logs into their laptop using fingerprint authentication or a PIN code—under these conditions, the FSSO-based policy is bypassed, and unrestricted access (e.g., to websites like YouTube) is allowed.

I would like to understand the root cause of this behavior and whether there is a viable solution to address it.

1 REPLY 1
rbraha
Staff
Staff

Hi @Reshans 

Probably when user login with with fingerprint or PIN it skips the default method for generating user event logs when logging to domain controller, so IP to username mapping is not created in FortiGate then it can hit bypass policy or any mismatch policy.

I think better option will be using FSSOMA and FortiAuthenticator where the agent send information to CA in this case FortiAuthenticator regardless of method used to login ,it supports Fingerprint,PIN,Biometric.. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors