Hot!FSSO - AD polling with 2 DC's

Author
emtee
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/06/12 22:36:50
  • Status: offline
2019/07/09 19:25:25 (permalink)
0

FSSO - AD polling with 2 DC's

If i have 2 domain controllers can i use AD LDAP polling mode? Or do i need to use the FSSO agents?

I am finding it's not polling all users logging in under the user event logs. Appears to be dependent on which domain controller they log on to. Even though it displays in the DC event logs on both servers, it only appears in the fortigate user logs for the DC the ldap connection is setup for.
 
Should i just use the FSSO agents and be done with it?
 
Cheers.
#1

3 Replies Related Threads

    hubertzw
    Gold Member
    • Total Posts : 192
    • Scores: 5
    • Reward points: 0
    • Joined: 2018/04/16 13:29:04
    • Status: offline
    Re: FSSO - AD polling with 2 DC's 2019/07/10 02:08:54 (permalink)
    0
    Do you have collector or only FGT + DC?
    #2
    Alivo_ FTNT
    Silver Member
    • Total Posts : 71
    • Scores: 22
    • Reward points: 0
    • Joined: 2013/04/30 12:42:47
    • Location: Fortinet TAC Prague
    • Status: offline
    Re: FSSO - AD polling with 2 DC's 2019/07/11 00:52:16 (permalink)
    0
    "Should i just use the FSSO agents and be done with it?"


    I'd say yes. There are good advantages over polling from FortiGate such as:
    1. Offload the task of getting logons to the Collector Agent(s) thus server CPU/Mem
    2. More Event IDs are suported polling from FortiGate > 4768, 4769.
        From Collector Agent(s) 672, 673, 680, 4768, 4769, 4776, 4624
    https://kb.fortinet.com/kb/documentLink.do?externalID=FD36424
    3. Ignore list > helps with logon overrides done by service accounts
    4. Better for troubleshooting
    5. Suitable for Large networks
    6. Workstation checks for added security
    7. Configurable IP address change checks for when user changes networks (typically wire/wifi)

    ...to name few
    #3
    Ricardo Tomas
    New Member
    • Total Posts : 12
    • Scores: 0
    • Reward points: 0
    • Joined: 2016/02/19 04:22:48
    • Status: offline
    Re: FSSO - AD polling with 2 DC's 2019/07/11 02:39:04 (permalink)
    0
    "Should i just use the FSSO agents and be done with it?"
    Awnser: Yes.
     
    But if you can't (like my case) you have to pull all DC's you have doing Authentication and Accounting.
    #4
    Jump to:
    © 2019 APG vNext Commercial Version 5.5