Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ipsectunnel
New Contributor II

Policy with subnet ranges and FSSO groups not working.

Hi

 

I have a 400F Fortigate with v7.4.9 build2829 (Mature). There is a policy that has always worked but since the upgrade to the current firmware I have had issues with users reporting no internet however once i remove the FSSO group from the rule internet access is restored. Both LDAP server show connection status as successful. Both external connectors are up. Collector agent status is running.

4 REPLIES 4
AEK
SuperUser
SuperUser

Hi

Did you upgrade the FSSO agent? 5.0 build 0323 and later is required.

Check here:

https://docs.fortinet.com/document/fortigate/7.4.9/fortios-release-notes/242321

AEK
AEK
ipsectunnel
New Contributor II

Hi AEK

 

Yes, the agent is on the correct version. What I did was disable the rule that always was working and create a new one identical to the old one and the new one is working fine so far.

Sheikh
Staff
Staff

Hello @ipsectunnel 

 

By enabling these debugs on Firewall, would give more details about auth failures.

# diag deb reset

# diag debug console timestamp enable
# diag deb app authd -1

# diag debug app fssod -1
# diag deb en

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
mrsimon007
New Contributor III

Hi I have a 400F Fortigate with v7.4.9 build2829 (Mature). There is a policy that has always worked but since the upgrade to the current firmware I have had issues with users reporting no internet. However, once I remove the FSSO group from the rule, internet access is restored. Both LDAP servers show connection status as successful, both external connectors are up, and the collector agent status is running. :backhand_index_pointing_right: For a step-by-step FortiGate FSSO troubleshooting guide, check this detailed resource.Hi I have a 400F Fortigate with v7.4.9 build2829 (Mature). There is a policy that has always worked but since the upgrade to the current firmware I have had issues with users reporting no internet. However, once I remove the FSSO group from the rule, internet access is restored. Both LDAP servers show connection status as successful, both external connectors are up, and the collector agent status is running.  For a step-by-step FortiGate FSSO troubleshooting guide, check this detailed resource.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors