Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ipsectunnel
New Contributor II

Policy with subnet ranges and FSSO groups not working.

Hi

 

I have a 400F Fortigate with v7.4.9 build2829 (Mature). There is a policy that has always worked but since the upgrade to the current firmware I have had issues with users reporting no internet however once i remove the FSSO group from the rule internet access is restored. Both LDAP server show connection status as successful. Both external connectors are up. Collector agent status is running.

3 REPLIES 3
AEK
SuperUser
SuperUser

Hi

Did you upgrade the FSSO agent? 5.0 build 0323 and later is required.

Check here:

https://docs.fortinet.com/document/fortigate/7.4.9/fortios-release-notes/242321

AEK
AEK
ipsectunnel
New Contributor II

Hi AEK

 

Yes, the agent is on the correct version. What I did was disable the rule that always was working and create a new one identical to the old one and the new one is working fine so far.

Sheikh
Staff
Staff

Hello @ipsectunnel 

 

By enabling these debugs on Firewall, would give more details about auth failures.

# diag deb reset

# diag debug console timestamp enable
# diag deb app authd -1

# diag debug app fssod -1
# diag deb en

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors