Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ahmedhamdy
New Contributor II

Profile internet access

There is a problem facing us, which is that users suddenly lose their access to Internet pages. The problem is solved by the user entering a server from any of the local network servers, and then accessing the Internet is restored to him. My question is what causes the user to lose his permissions and lose communication between him and Active Directory.

10 REPLIES 10
hbac
Staff
Staff

Hi @ahmedhamdy,

 

Are you using FSSO? 

 

Regards, 

ahmedhamdy
New Contributor II

yas using FSSO Kindly give solutions to help

hbac

@ahmedhamdy,

 

You can refer to this article at step 4) User was authenticated but got sporadically or intermittently deauthenticated at one point in time. 

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FSSO-CA-initial-troubleshooting/ta-p...

 

Regards, 

ahmedhamdy
New Contributor II

Thank you for your cooperation

AnthonyH
Staff
Staff

Hello ahmedhamdy,


While the issue is occurring could you run these debugs and replace <source_ip> with the users ip and have them attempt to ping 8.8.8.8 as an example? The logs should indicate what policy is being matched.

di deb disable
di deb res
diagnose debug flow filter clear
di deb flow filter addr <Source_IP>
dia debug flow filter proto 1
diagnose debug console timestamp enable
diagnose debug flow trace start 9999
diagnose debug enable

Technical Support Engineer,
Anthony.
ahmedhamdy
New Contributor II

Kindly add more due to lack of understanding

Shashwati
Staff
Staff

Are you using LDAP server on Firewall to authenticate user ? 

ahmedhamdy

Kindly give solutions to help

ahmedhamdy

yas using LDAP server

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors