Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dieter
New Contributor

FSSO agent ip exclusion

Is there a way to exclude certain IP addresses from collecting authenticated users ?

10 REPLIES 10
xsilver_FTNT
Staff
Staff

Hi,

 

dieter wrote:

Is there a way to exclude certain IP addresses from collecting authenticated users ?

 

yes

If your Collector is getting updates from some sources and you do not want those sources to collect authenticated users, then options are:

 

1. if in DCAgent mode simply uninstall agent from those DCs when you do not want auth info from

2. if in polling mode then remove DC from polled controllers

3. list of polled DCs is in "dc_list"="" key

4. list of connected/known DCAgents is on the end of exported config from Collector

5. you can ignore updates from certain DC via "dc_agent_ignore_ip_list"="" key

6. all the keys are in [HKEY_LOCAL_MACHINE\software\fortinet\fsae] sub-tree .. 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

dieter

dc_agent_ignore_ip_list seems to be an undocumented feature. But it seems to work.

 

Thank you

dieter
New Contributor

Curious: In the Firewall User monitor I don't see users associated to the excluded IP addresses.

In Forward traffic log however, some traffic from those IP's have a user associated...

 

In User even log, I see FSSO logon/logoff events on the excluded IP's. Log off event for most users us about 3 seconds after logon event. Probably enough to have some traffic related to a user...

 

On 5.6.2 by the way.

Ackron
New Contributor

Hello all,

 

 I was wondering this myself, In our case we have multiple users being associated from the Wireless Lan Controller IP

As this is Wifi Logon they before they have an IP they get associated with the WLC IP. so we wanted to exclude the WLC IP from ever being associated to any user.

 

Kind regards,

Peter

xsilver_FTNT

Hi Peter,

point 5. from my original post .. "dc_agent_ignore_ip_list"="" is the answer.

 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

dfernturtle

Any documentation available on how to create this dc_agent_ignore_ip_list key if I have multiple IPs?

dieter

Separated by semicolons seems to work.

Not documented afaik.

Adrian_Lewis

Alivo__FTNT

It says: Subnets are not supported, each IP address must be entered individually. This should change soon.

 

Best Regards,

Alivo

livo

Labels
Top Kudoed Authors