Hi,
We currently have a Single Sign-On Agent installed on 1 DC, which is configured to monitor all DC's.
All works fine until a users switches from wired Ethernet to Wifi, they are no longer able to browse the internet. To solve this, they would need to lock the laptop and log-in again to windows. In the "Show Logon Users" the user will be listed with "wired" IP address and not Wifi IP.
I have tried reducing the "Workstation verify interval" to 1 minutes and the "IP address change verify interval" to 10 seconds but this did not solve the problem.
Firmware: v5.2.7,build718 on 300D
Solved! Go to Solution.
Hi eascolaro,
it heavily depends on DNS. Wifi adapter has to be able to send DNS update to DNS server you are using.
The feature used in this case is "IP change detection". It walks in the loop the logon list, and tries to resolve workstation name there. So if you move to Wifi, you must ensure DNS update reaches DNS server, it's reflected and DNS database is updated. Then, IP change detection feature will resolve workstation name correctly, containing fresh IP address and logon list is updated.
Fishbone )(
smithproxy hacker - www.smithproxy.org
Hi,
check or retest and pay extra attention to time when step 3) happened and what happened after in eventlog and Collector debug log.
If you just changed IP and re-connected cable.
Then if wifi was not disconnected then you should have 2 IP addresses on NTB > 2 IP in DNS.
If that change was not followed by any logon event spotted (time of "3)" step and later), then Collector will take up to "3)"+"registry DNSlookupinterval" (in GUI as "IP Address change verify interval (seconds)") time to realize that IP has changed.
Check sequences.
Tomas
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi Thomas,
The laptops are configured to disconnect Wi-Fi when Ethernet is connected. And when it senses the cable is unplugged it reconnects to Wi-Fi.
And even so, the "IP Address change verify interval (seconds)" is set to 10 seconds. So it should verify the IP after 10sec,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.