I'm using 5.4.1. I setup fsso and trying to view user activity in forward traffic logs but the user column is blank. I know it is seeing the user because the policy allows that user and the web-filter logs display the user. Is this just a cosmetic bug in 5.4.1 or am I missing something here?
Solved! Go to Solution.
So I got it to work by starting from scratch. This is what I did (maybe in not this exact same order)
I am using two domain controllers for this, not sure if it matters but this is my scenario
[ul]
The new policy I created has as the source an Address Group I created for my Citrix Servers and the FSSO group. I enabled the option to Log All Sessions. Once I got all this to work I enabled IPS, DLP, AV, Web-Filter, CASI. Once all that was working I enabled SSL/SSH Inspection.
Log & Report – User Events is your friend. Forward Traffic Log if you see the user and the icon is blue means that it was authenticated, if it is red it wasn’t.
I am having the same issue. I have a Citrix environment and when I check the Source column I see the username with the server name in there, but when I check the user column it is empty.
Hi good day,
I'm actually here because of the same issue, I’ve also setup fsso (polling) and added my users and groups but no user is showing up in the user column when I check the forward logs. Plus, I'm running the explicit proxy feature so I tried creating a user authentication policy to user Kerberos but anytime I hit apply the settings doesn’t save…….
Can someone please help with this issue? I would really love to log user activity with active directory users.
So I got it to work by starting from scratch. This is what I did (maybe in not this exact same order)
I am using two domain controllers for this, not sure if it matters but this is my scenario
[ul]
The new policy I created has as the source an Address Group I created for my Citrix Servers and the FSSO group. I enabled the option to Log All Sessions. Once I got all this to work I enabled IPS, DLP, AV, Web-Filter, CASI. Once all that was working I enabled SSL/SSH Inspection.
Log & Report – User Events is your friend. Forward Traffic Log if you see the user and the icon is blue means that it was authenticated, if it is red it wasn’t.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.