Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
globatech
New Contributor

Port 8000 for SSO is closed

Hi,

im having a issue with my web filtering profile that is not active on my Fortigate. Only the default profile works for all users. I dunno if it was the problem, but on my FSSO agent ive enter the default port 8000 to connect to the Fortigate Unit. But when i do a NMAP on my Fortigate the port 8000 is CLOSED. Do you thinks thats why the users cant have their right profile applied for web browsing? If so how do i open it? Thanks!

3 REPLIES 3
pcraponi
Contributor II

The port 8000 used are on your FSSO Server. Not on Fortigate.... Fortigate did a connection on port 8000, not receive it...

 

Check if your server with FSSO installed not have any Firewall (like the Windows default Firewall)...

 

http://kb.fortinet.com/kb...ateId=0%200%2067318832

 

regards,

Paulo Raponi

Regards, Paulo Raponi

Regards, Paulo Raponi
globatech

Thanks for the reply and the explanation about the port 8000. On my server the domain firewall was disable. Im starting having this issues since have update to os 4.x to the 5 version. On my server i see all the events in my logon user log, but it seem to have a problem with the communication between the fortigate and the server. On my fortigate have set up the user profile. Ive create too the user group that are linked to the AD filtering group and all that was place in a filtering firewall user policy but all user still take the default policy.... any other idea? Thanks

iJake
Contributor

Has this been resolved?

--

Are you seeing the users groups from AD under the FSSO config on your FortiGate?

Are you seeing users authenticated on your FortiGate?

 

diag debug authd fsso list

 

This will list authenticated users, if there aren't any, there's a communication issue between the FortiGate and the Collector Agent. Did you upgrade your Collector Agent when you upgraded your FortiGate to v5?

......

-Jake

...... -Jake
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors