Description This article describes the migration of the
FortiAuthenticator-VM to a new FortiAuthenticator-VM and what is the
token behavior after migration. Scope FortiAuthenticator VM 6.5.3
Solution There are two main VM migration types: Same platfo...
Description This article describes a possible workaround for FSSO
authentication from Windows 11 clients. Scope Windows 11. Solution There
are two issues observed with FSSO authentication after users upgrade to
Win11. Starting in Windows 11, version ...
Description This article describes how to uninstall the FSSO DC, TS, and
Collector Agent in the Domain Controller. Scope Windows Server 2019,
FSSO version v5.0. Solution Uninstall DC Agent: Stop the FSAE service
and set it to manual or disabled: Go t...
Description This article describes all the services that are possible to
enable on the FortiAuthenticator interface and why they are configured.
Scope FortiAuthenticator. Solution As a best practice, it is advised to
enable only the services used. He...
Description This article describes the upgrade procedure of the
FortiAuthenticator HA cluster for individual nodes. Scope
FortiAuthenticator in HA pair configured as Active-Passive Cluster.
Upgrade on each FortiAuthenticator cluster member individual...
Are these two alerts coming for same not existing user or happens with
every user you are trying to assign token ?Do you have available tokens
to assign ?Does this user has a defined email on the remote LDAP ?
Please provide full logs shown, it must ...
Hello, Negotiation timeout can happen for many reasons. Did it ever work
for those clients ? Or is the issue intermittent? If Not,Are those peers
same type devices ? What vendor/client? I believe best next action is to
take a packet capture. Definite...
Hello @GiangNH , In addition to @ndumaj From explanation "Still keep
remote LDAP user xxx though it has ceased existing remotely" it looks
like this user is not existing anymore on the remote server but still
exists in FAC Looks like related to this ...
Hello Jack, Thank you for your update. a)I believe option "Group
attribute" under query elements is how do you want obtain the group
membership for a user. b)User attributes here means what user attributes
from remote LDAP should we populate when imp...
Can you please show me the logs regarding this activity from : Logging >
Log Access > Logs We should have some info there for this import for
example : Please click each log entry so we can see the message
displayed for each of them. Alternatively, y...