Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ravi2504
New Contributor

FSSO - Cross Domain Configuration

Hi All,

 

We currently have 3 separate domains configured with a Two-Way Non Transitive Trust between each domain.

 

Each domain has it's own Fortigate 300D which serves internet access for that domain.

 

The FSSO agent is set to use Polling Mode - Poll Sessions using Windows NetAPI from 6 DCs (2 DCs per domain) and is set to monitor all three domains, group filiters have also been configured.

 

Problem occurs when a user from domain A logs onto domain B at initial logon, everything works as expected, however, after a period of time it seems as though the user drops off the fortigate, the problem rectifies itself eventually or the user will have to log off and log back on.

 

I tried to change from NetAPI to DC Agent Mode at each site the DC Agent mode works but unable to work across sites, when trying to configure we get the following errors 

 

Failed to modify remote registry --> Create remote share error: 5 paramerr=0 --> Failed to Copy file to remote machine , then it eventually errors out with Failed to install DC Agent on domain controller: XXX.XX. Please check you have sufficient right to copy file and modify registry of the domain controller.

 

When I also change to poll using WMI, it seems to drop the logons.

 

Please help.

3 REPLIES 3
xsilver_FTNT
Staff
Staff

Hi ravi2504,

 

1. it seems to me that installation of the DCagent form Collector to other domains and respective DCs fail because account under which Collector runs and/or your account, if install don manually, do not have domain admins rights in those other DCs/Domains.

 

2. switch Collector log level to debug and in the log you will probably see that those users from domain A are dropped off the fsso user list as they fail either in workstation check, or in DNS resolution of their workstation name in domain B where they logged in.

Because if user from domain A, logs to workstation in domain B, then domain B Collector will add user's domain (A) into workstation's name and will try to resolve workstationB.domainA in DNS (for user from domain A).

 

If this #2 is the case then set domains in Collector's suffix list so Collector will try to resolve workstation in all those domains.

[HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FSAE\] workstation_suffix_list=domaina;doaminb

Alternatively you can make DNS records the way that workstationB is resolvable as in domainA as well.

 

Best regards,

Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

ravi2504

can I add in the additional suffixes in the FSSO collector Agent Advanced settings, instead of the registry change?

xsilver_FTNT

sure, sorry I haven't mentioned that. I'm kind of used to use registry keys.

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Labels
Top Kudoed Authors