Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
claumakurumure
New Contributor III

Internet Access via FSSO does not work after 16:00.

For some reason users get kicked out after 16:00 GMT +2. Has anybody experienced something simillar FSSO is running in polling mode and the client has 7 DCs.

 

Please assist

hezvo uko
hezvo uko
2 REPLIES 2
xsilver_FTNT
Staff
Staff

if the users usually log in at around 0800, and get de-authenticated at around 1600

if they are seen in collector agent as "Not Verified"

then you had probably hit dead entry interval, which is by default 8 hours

 

check workstation checks and verifications and that

- on workstation is Remote Registry Service running

- collector was installed and runs under Domain Admins group member account

 

Combiation of above should make users Verified in collector and therefore not falling out of the list due to failed verification and dead entry timer timing out.

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

claumakurumure

As per the Fortinet doc I set the deantry interval to 0 but I have found that those users were also on NTLM authentication it looks like if I get this out then I will have won.

hezvo uko
hezvo uko
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors