Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fred339
Contributor

Fortigate FSSO with Windows AD - Windows Firewall Settings

I'm looking for a definitive list of settings for Windows firewall when using FSSO in common situations:

- Collector Agent running on Domain Controllers: so, Domain Controller Firewall Settings

- Collector Agent running on a separate Windows computer: so, Domain Controller Firewall Settings and Collector Agent Computer Firewall Settings.

- Domain Windows workstation Firewall Settings.

- any others?

Links will be fine of course!

Thanks!

Fred Marshall
Fred Marshall
2 REPLIES 2
distillednetwork
Contributor III

Here is a list of FSSO firewall ports used based on the service used.

 

https://docs.fortinet.com/document/fortigate/6.4.0/ports-and-protocols/879117/fsso-fortinet-single-s...

 

aahmadzada
Staff
Staff

Would definitely suggest avoid using the  build in fsso poller(AD Connector) as it has a lot of limitations and usually used only for test/demo purposes.
FSSO Collector agent on the other side has wide range of settings and flexibility, is scalable and robust compared to the local poller. List of differences can be found here:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-local-poller-fssod-limitations-compar...

Ahmad
Labels
Top Kudoed Authors