Hi
I have a customer with the following issue:
Fortinet Single Sign On uses DNS records for authenticating client end points to the firewall. The initial connection whether made using a cable or wifi connects ok, once the end point switches from cable to wifi the IP address/MAC changes, hence DNS records for the host are out of date.
DNS changes for the host following network adaptor has been switched update within seconds at the site the host is connected to. The DNS changes are not replicated to another site so quickly and can take up 10-15 minutes. This wouldn¿t normally be an issue but the FSSO agent can only run on one DomainController at a time, it does not support load balancing or clustering. Therefore if a client connected to a Domain controller at a site where the FSSO agent is not running it can take 10-15 minutes for the DNS to update and FSSO authenticate the client. The result means users lose internet connectivity until the DNS records are updated.
Has anyone ever come across this and aware of how it could be fixed?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1066 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.