Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
IvarR
New Contributor

Fortigate logs - kerberos srcname

Hello,

I have weird issue where if "device identification" is enabled on interface and Fortigate gets hostname information from kerberos traffic it adds some spaces after the hostname. It can also be seen from 'diagnose user device' command like this:

vd root/0 54:e1:ad:xx:xx:xx gen 390881 req 0
created 7078125s gen 83715 seen 1637670s SW123 gen 15618
ip 192.168.10.123 src arp
os 'Windows' src http id 1444 weight 130
software version '10' src http id 1444 weight 130
host 'PC-TEST123456   ' src kerberos
user 'test.user' src kerberos

 

It always seems to add spaces so field is 16 characters long.

Is this issue with Fortigate or something with way Windows communicates through kerberos? Haven't been able to figure this out myself.

3 REPLIES 3
Stephen_G
Moderator
Moderator

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

If anyone has any advice to contribute, please do!


Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP. If anyone else has any information, please feel free to contribute it!


Thanks,

Stephen - Fortinet Community Team
ebilcari
Staff
Staff

Try to reproduce the behavior after enabling this debug:

# diag debug application cid -1

# diag debub ena

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors