Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nick1001
New Contributor

SSO DNS update time issue

Hi

I have a customer with the following issue:

 

Fortinet Single Sign On uses DNS records for authenticating client end points to the firewall. The initial connection whether made using a cable or wifi connects ok, once the end point switches from cable to wifi the IP address/MAC changes, hence DNS records for the host are out of date.

DNS changes for the host following network adaptor has been switched update within seconds at the site the host is connected to. The DNS changes are not replicated to another site so quickly and can take up 10-15 minutes. This wouldn¿t normally be an issue but the FSSO agent can only run on one DomainController  at a time, it does not support load balancing or clustering. Therefore if a client connected to a Domain controller at a site where the FSSO agent is not running it can take 10-15 minutes for the DNS to update and FSSO authenticate the client. The result means users lose internet connectivity until the DNS records are updated.

 

Has anyone ever come across this and aware of how it could be fixed?

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors