Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yeowkm99
Contributor

2nd FSSO agent

Is it really necessary to have a 2nd FSSO agent on the fortigate as colllector agent?

i am trying to setup a 2nd AD as FSSO agent.

what will happens if the main FSSO agent server is rebooted or went down?

 

d123a5f3-b2c3-446a-a340-03a61075cde8.jpg

2 REPLIES 2
ozkanaltas
Contributor III

It depends on your needs. If the main agent is going down, Fortigate collects data from the second agent. If you don't have a second agent, Fortigate doesn't know who logged in recently. Because of that, new logged-in users can't access resources that are processed with FSSO rules. Also, Users who are already logged in can continue to access resources until the cache expires.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
akanibek
Staff
Staff

For more details, please have a look to the KB article below. I would also remark both FSSO CAs should be synced with polling hosts, group filters, and ignore user lists:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FSSO-Collector-Agent-failover-behavior/ta-...

Asset
Labels
Top Kudoed Authors