Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Charl_Schippers
New Contributor

SSO with Remote Desktop

Hello, I would like to configure a Remote Desktop Server with SSO to Internet Explorer with a AD Windows 2008 R2. The problem is that the Fortigate can only SSO with one user, and that is the first user who connects to internet Explorer. Because the fortigate connects with the ipaddress, there is only one user registred. The other RDS users can connect to the Internet with the same user is. I configure also the ip virtualization on the RDS server, but that is not a solution. Can someone tell me how we can do this ? Regards,
7 REPLIES 7
Carl_Wallmark
Valued Contributor

You should use the " Terminal Server agent" found in FSSO for FortiOS 5 Have a look in the FSSO folder.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Charl_Schippers
New Contributor

Is this also working with Fortigate mr3 PAtch 14?
Carl_Wallmark
Valued Contributor

No, I dont think so, its a new feature for FOS 5, but I could be wrong.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
pello
New Contributor II

its a new feature for FOS 5, but I could be wrong.
Correct! Implementation FOS side was first delivered in 5.0.1.
Antonio_Milanese

You should use the " Terminal Server agent" found in FSSO for FortiOS 5
Yes FOS 5 new feature but not well documented ihmo at least not on current KB, end user documention.. anyway you' ve to: 1) install TS Agent service on each RDS server 2) point TS Agents to your regular FSSO collectors 3) set a range of system ephimeral ports from which user sessions will be allocated 4) Under collector " show logons" log you' ll see those users as RDS_SERVERIP:TSAGENT_SESSIONID with a range of ports associated Essentially, if I' ve understood correctly each new user winsock it' s allocated from a fixed pool of ephimeral source tcp/udp ports that univocally identify user sessions.. Beware of S.O. differences that I' ve encountered: - on Windows 2008 or above, system dynamic udp/tcp are allocated on range 49152-65535 (and controlled via netsh) so TS Agent detect a valid free range under 49150 - on Windows 2003 range limt it' s not configured by default so you' ve to change it writing a key into the registry Regards, Antonio
Silver
New Contributor

Dear All,

 

Anyone can confirm me when configure TS Agent under SSO collector agent IP/Port if we are having only one Collector agent we need to configure same like 192.168.1.10 or 192.168.1.10:8002 and if for 2 collector agent we need to configure same like 192.168.1.10:8002;192.168.1.20:8002 or 192.168.1.10,192.168.1.20.

 

Regards,

Awaiting reply.

Silver
New Contributor

Any feedback plz

Labels
Top Kudoed Authors