Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ismailurek2
New Contributor III

Manage 2 different domains on a single server with a single FSSO

Hello,

 

We are currently running two FSSO agents for two different domains on two different servers under these domains. Is it possible to query two different domains from a single server with a single FSSO agent? Is it possible to install two different FSSO agents on a single server? What is the best practice method for this?

 

Regards,

1 Solution
pminarik
Staff
Staff

If you're talking about two completely separate domains, then as far as I know this is considered to be a pretty bad idea.

 

Last time I have seen this discussed, it was possible in theory, but with a lot of hacks and workarounds.

  • DC Agent only (Collector from domain-x could not properly authenticate to DC's on domain-y to read event logs, therefore no event polling or netapi)
  • No workstation check (same auth issue as above)
  • The other domain had to be manually added through registry edits (the Collector GUI doesn't permit manual addition)

 

>  Is it possible to install two different FSSO agents on a single server?

No. While you may be able to install them in different directories, and manually run two separate services for them, they use static registry paths for config, and thus the two collectors would be fighting over one settings and overriding each other. (~and thus both trying to use the same IP:port)

 

Good practice is separate, independent collectors for separate, independent domains.

[ corrections always welcome ]

View solution in original post

2 REPLIES 2
pminarik
Staff
Staff

If you're talking about two completely separate domains, then as far as I know this is considered to be a pretty bad idea.

 

Last time I have seen this discussed, it was possible in theory, but with a lot of hacks and workarounds.

  • DC Agent only (Collector from domain-x could not properly authenticate to DC's on domain-y to read event logs, therefore no event polling or netapi)
  • No workstation check (same auth issue as above)
  • The other domain had to be manually added through registry edits (the Collector GUI doesn't permit manual addition)

 

>  Is it possible to install two different FSSO agents on a single server?

No. While you may be able to install them in different directories, and manually run two separate services for them, they use static registry paths for config, and thus the two collectors would be fighting over one settings and overriding each other. (~and thus both trying to use the same IP:port)

 

Good practice is separate, independent collectors for separate, independent domains.

[ corrections always welcome ]
ismailurek2
New Contributor III

Hi @pminarik ,

Thank you for your information.

Regards,

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors