Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
quevedo_lopez
New Contributor

Redundant LDAP Servers - FSSO

Hi,

I need to configure a FSSO with a redundancy on LDAP servers, a second server of AD for Failover.

 

Thanks in advanced.

3 REPLIES 3
xsilver_FTNT
Staff
Staff

Hi,

how about to have one FSSO Collector agent installed on first DC, asking local LDAP. Plus second FSSO Collector on second DC also asking local LDAP. And then have those two Collectors in one FSSO Agent setting in FortiGate. So when one Collector became unreachable then second one will be used until it fails as well.

 

So when local LDAP on any of DCs fail, then local collector will fail most probably as well as DC will be in more serious troubles then Collector not running.

This is usual scenario for FSSO resilience.

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

jimzky1026
New Contributor

Try to open this link and follow instructions...

https://kb.fortinet.com/k....do?externalID=FD39911

scerazy
New Contributor III

Yes, that is the "normal" working setup

Labels
Top Kudoed Authors