Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor

What is the best choice for FSSO


Which is the best way to use FSSO when I just have one Windows DC ? I saw that it is possible to configure the fortigate only to "query" the AD and nothing has to be installed on the AD. It is a good choice to just install the collector directly on the AD if I just have one AD ? Is the collector useful when there is just one AD ? 


Thank you in advance for your responses




Is there a limit on how many DC's can you poll directly from FortiGate?





Well .. there are limits governed by max. values table .. but in fact I would not poll from FGT at all, or for very, very small domain environment. Let's say one DC.

Use standalone Collector Agent on DC or any domain member to do WinSec+WMI polling, or DCAgent, or mix of polling and DCAgent. That's much better and more scale-able solution. And Collector is distributed free of charge alongside with FortiOS on support portal.

Tomas Stribrny - NASDAQ:FTNT - Fortinet stuff - TAC L3 Escalations engineer