Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Vishalv16
New Contributor

FSSO configuration on Secondary Domain controller

I need to install  FSSO agent & DC agent in secondary DC. in primary DC FSSO client is their & sync with fortigate   now we are installing DC FSSO agent on 2nd DC but we did not restart the DC its not sync with fortigate does restart is needed ? I just want to configure 2nd DC in fortigate in case primary fails. also at the time of installing collector agent we give option to select domain controller do we need to select both domain controller or only one that we installing the collector agent on. ( also user facing an issue after installing FSSO agent on 2nd Dc but haven't restart th DC system & does not sync with fortigate hence many user are losing internet access in middle on session does currently its uninstalled from secondary DC) Thanks in advance

[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2

[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
1 Solution
xsilver_FTNT
Staff
Staff

Hi,

if you do have one or few domains, but all those are going to be handled by 2 Collector Agents (handling same domains) and you run this in with DCAgents, then in short:

- you might have 2 Collector Agents installed on domain member computer, DC is preferred, for resiliency

- you need to ave DCAgent installed on every DC which might be used as logon server (usually all DCs)

- you have to have those DCAgents set to report to both (all) your Collector Agents, so both collectors will have same logons from those DCAgents, no matter where those logons happen

- and finally you have those two collectors set inside a single FSSO Agent on FortiGate(s).

 

This is FSSO Agent setting on FGT is a list. One and only one of listed Collectors is used on FGT until connection to that collector fail. Then next in list is connected and used, till this one fail. When last on list fails, first is used again. List is cyclic. There is connection to only one "serving" collector per FGT at a time. There is no primary, or backup collector, neither master/slave. All collectors are equal and not syncing. No fallback to previous 'master' as there is no master collector. Those are standalone, independent units.

 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

View solution in original post

2 REPLIES 2
xsilver_FTNT
Staff
Staff

Hi,

if you do have one or few domains, but all those are going to be handled by 2 Collector Agents (handling same domains) and you run this in with DCAgents, then in short:

- you might have 2 Collector Agents installed on domain member computer, DC is preferred, for resiliency

- you need to ave DCAgent installed on every DC which might be used as logon server (usually all DCs)

- you have to have those DCAgents set to report to both (all) your Collector Agents, so both collectors will have same logons from those DCAgents, no matter where those logons happen

- and finally you have those two collectors set inside a single FSSO Agent on FortiGate(s).

 

This is FSSO Agent setting on FGT is a list. One and only one of listed Collectors is used on FGT until connection to that collector fail. Then next in list is connected and used, till this one fail. When last on list fails, first is used again. List is cyclic. There is connection to only one "serving" collector per FGT at a time. There is no primary, or backup collector, neither master/slave. All collectors are equal and not syncing. No fallback to previous 'master' as there is no master collector. Those are standalone, independent units.

 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Vishalv16
New Contributor

Hi Tomas, thank you so much for so much. it help a lot to understand how fortigate FSSO works Regards Vishal Rathod

[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2

[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
Labels
Top Kudoed Authors