Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mbutler522010
New Contributor

FSSO and laptop sleep

I am having trouble with Windows laptops and sleep, when they come out of a long sleep they don't get authenticated at the firewall and have to reboot. Then all is fine

 

Our setup:

Aruba controller using Radius authentication

Microsoft Server with NPS and Active Directory

Fortigate firewall with FSSO and rules defined by user group memberships.

 

All works well on initial boot/login, my guess is what is happening with sleep is:

[ol]
  • laptop resumes from sleep
  • Wireless networking probably not working yet, so the user authenticates with cached credentials
  • Aruba/Windows finally get it all worked out and restore connectivity. User can surf inside the firewall.
  • I don't know if the Windows machine sends an after-the-fact "I used cached credentials, so the user is authenticated" message to the Domain Controllers
  • User tries to use Internet
  • FSSO checks log, no recent login, no group membership, user denied[/ol]

     

    Is FSSO too limited in this case, would I need to switch to RSSO?

    Mark

  • 1 REPLY 1
    bdarcyevans
    New Contributor

    Hi Mark, how did you go with this? We've just installed a couple of FortiGate's and are having this same issue on wireless Windows clients resuming from sleep. Interested to know if you ever found a solution or more user convenient workaround.

    Labels
    Top Kudoed Authors