Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

Primary & Secondary Failover

Hello Fellas,

 

I have 4 AD server in my network, I installed 2 Collector Agent to my 1st and 2nd AD Server for failover purposes and DC agent to the remaining 2 servers.

Is there a way in FSSO settings or AD server that once Primary AD goes down in less than a minute Secondary will handle the authentication semlessly?

In my lab once I disconnected my Primary AD it take some time Foritgate recognizes the secondary server.

I was thinking similar to WAN link load balance there is ping server where to trigger the failover method.

 

Any feedback is much appreciated.

 

BR,

 

 

Fortigate Newbie

Fortigate Newbie
5 REPLIES 5
Fishbone_FTNT

Hello Fullmoon,

this is matter of protocol timers, which can't be tuned from Fortigate/FSSO CA configuration. Could you please let me know how long it takes in your case to fail-over to next FSSO CA and why it is that not fast enough for you?

 

Thanks,

 Fishbone

smithproxy hacker - www.smithproxy.org

Fullmoon

hi Fishbone,

 

Appreciate your inputs.

Here's the outcome of my re-testing while ago.

Double checked my FSSO Agent/IP status and it was pointing to Primary AD.

Both my Primary and Secondary are up and running, on computer 1 and computer continuously pinging both server ip and yahoo.com. shutdown the Primary server, computer 1 and computer 2 still can browse the internet but loading of pages took so long, under Fortigate->Single Sign On->checked FSSO Agent/IP status still pointing to Primary AD, based on my observation it took 3-5 mins before FSSO Agent/IP recognized Secondary AD Server IP.

 

BR,

 

Fortigate Newbie

Fortigate Newbie
emnoc
Esteemed Contributor III

For a quicker  failover do you have any internal SLB and can build a virtual server with LB algorithim and a layer4 port check?

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Fullmoon
Contributor III

hi emnoc, appreciate also your inputs. that's the first idea comes into my mind but as of now we don't SLB device running on our network.

 

Fortigate Newbie

Fortigate Newbie
Fishbone_FTNT

Hi Fullmoon,

I am not sure of loadbalancing will help here. Fortigate<->FSSO CA connection is long-term  connection, so it's unlikely you will benefit from having it.

What is strange is that 3-5 minutes, that's a lot. How was that shutdown performed? If the tcp connection is closed normally, second FSSO CA should take over instantly. If you just unplugged server from network, it would mean that it's up to protocol to detect connection is lost, in that case it can be some minute or so (there are keepalives sent inside of FSSO protocol, one side is 10s and another 60s).

The slow browsing experience would lead me to different problem, I don't think FSSO can influence this. Isn't your first FSSO CA (you were shutting down) also primary DNS server?

 

Cheers,

 Fishbone )(

smithproxy hacker - www.smithproxy.org

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors