At random moments, a user is incorrectly recognized by FSSO and does not receive the permissions they should. This happens sporadically but has been occurring more frequently lately.
FSSO and the DC Agent are installed on each Domain Controller. They are configured so that each FSSO monitors all domains.
Regarding the FortiGate configuration, the primary connection is set to the first DC, while the second DC is configured as a backup.
FG ver 7.2.11
Collector Agent version: 5.0.0319
DC agent version 5.0.0315
Does it occur when a user switches from Ethernet to WiFi?
Otherwise can you provide more info on the context and the behavior?
Yes, after turning off the user's WiFi and connecting via Ethernet, the issue has been resolved for now. The user falls under the appropriate policies.
You are probably hitting a known case due to DNS update. The following solution and tech tip by @xsilver_FTNT should help.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.