Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
msalhi
New Contributor

FSSO agent file

Dear Experts,

 

May I know what is the different between  FSSO DCAgent_Setup_5.0.0264.exe and FSSO_Setup_5.0.0264.exe ,I have One domain controller server and I want just simply install the FSSO on int DC  and pull the users from there ,which file should I install?

 

 

5 REPLIES 5
xsilver_FTNT
Staff
Staff

Hi,

use FSSO_Setup file as it is so called Collector Agent, which (if you choose DCAgent mode) will spawn DCAgent installation as well as it is included in this package.

 

The FSSO DCAgent_Setup is the standalone installer for DCAgent only. This is helpful if you would like to (re)install DCAgent on some DC manually and not via Collector Agent.

 

Basically you need at least one Collector completing data about users and workstations and pushing those aggregated data (FSSO user list) into connected FortiGate unit(s). You can run Collector in multiple modes, one of them is DCAgent mode and in this case you'll need to install DCAgent part/component onto every DC in the domain and point them to Collector so they'll know where to report spotted user logons.

 

Best regards,

Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

msalhi

Hi Tomas,

 

Great, So We I have to install the collector Agent (FSSO Setup file) even I have one DC ,right ?

 

 

Thanks

xsilver_FTNT

Hi,

if you are not going to poll DC directly from FortiGate.

If you do not have FortiAuthenticator as collector agent.

Then you need to install at least one Collector Agent somewhere in domain.

Preferably on DC, and under Domain Admins group member account (do not need to be Administrator direcly, Domain Admins member user account made specifically for the FSSO use is OK).

 

Best regards,

Tomas

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

KCH

Please Tomas, When you upgrade your firewall 5.6.0 to 5.6.3 ; Are you forced to reinstall the fsso client on the AD?

I have a probleme with fsso session because After upgrade to 5.6.3, no fsso session is monitor on the fortigate

xsilver_FTNT

That should not be needed.

It makes no sense to reinstall AD FSSO components (unless you migrate from FortiOS 4x to 5.x and so from FSSO 4.x to 5.x which happend quite a while ago).

 

I'd suggest to set Collector to debug log level and check the log.

Also on FGT 'diag debug auth fsso server-status' .. if it's connecting then there is either broken password for auth between FGT and Collector or something else broken more deeply (then open a ticket of FTNT support to check).

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Labels
Top Kudoed Authors