Hot!FSSO - collector agent - set group filters

Author
hubertzw
Gold Member
  • Total Posts : 202
  • Scores: 3
  • Reward points: 0
  • Joined: 2018/04/16 13:29:04
  • Status: offline
2020/10/23 01:30:35 (permalink)
0

FSSO - collector agent - set group filters

Hi
do you know what is the max number of entries in the 'set group filters'?
 
#1

7 Replies Related Threads

    Alivo_ FTNT
    Expert Member
    • Total Posts : 97
    • Scores: 50
    • Reward points: 0
    • Joined: 2013/04/30 12:42:47
    • Location: Fortinet TAC Prague
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/23 07:30:44 (permalink)
    5 (1)
    Hi,
     
    This info is here:
     
    https://docs.fortinet.com/max-value-table
    select FortiOS, FortiGate model and search for adgrp
     
    Best Regards,
    Alivo
    #2
    hubertzw
    Gold Member
    • Total Posts : 202
    • Scores: 3
    • Reward points: 0
    • Joined: 2018/04/16 13:29:04
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/24 06:54:01 (permalink)
    0
    Hi
     
     thought the value adgrp shows how many AD groups you can have on particular device. In my case there is AD with >5000 groups and to save smaller devices I don't want to send them all logged users, just some groups. With close to 8000 devices I have to add at least 1 filter entry, in the collector agent, for each device. My question was: is there any limit? With just 1-2 entries per device I need 8000-16000 filter entries. Can I do it on one collector or maybe because of some limits I need more collectors?
     
    I mean the feature described in paragraph 3)
     
    https://kb.fortinet.com/kb/documentLink.do?externalID=FD36607
     
    Thanks
    #3
    xsilver_FTNT
    Expert Member
    • Total Posts : 551
    • Scores: 147
    • Reward points: 0
    • Joined: 2015/02/02 03:22:58
    • Location: EMEA
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/26 05:06:52 (permalink)
    5 (1)
    Hi,
    ADGrp .. "config user adgrp" entries are either Group Filter records for standalone Collector Agent pushed as per-FortiGates' serial number specific filter (when your FGT do have LDAP in 'config user fsso' for respective Collector), or pulled from Collector Agent, if that collector do have per-FGT specific filter, or Default filter set and FGT do NOT have LDAP in settings.
     
    In either case how the records got to 'config user adgrp' those are USER GROUP records !!

    Therefore, those should NOT contain specific users or devices, those should point to GROUP type of objects which sort of consolidate all possible candidates.
    Because FSSO is based on group membership.
    Collector can read group membership from AD.
    Collector do not need to filter every single user via group filter and FGT then do not need to consolidate those single adgrp records into 'config user group' fsso type!
    It is not intended to duplicate groups known/defined on AD and I would consider this as configuration error.
     
    Goal of FSSO Group filter is to learn group membership from AD and let AD Admins to "drive" from AD level who is eligible to access what and through firewall (FortiGate), via group membership processed by Collector and users' membership shared to FGT (which then drive access privileges based on groups).
     
    So, if you want to grant access to specific users, then group them to some specific AD group.
    Then add this group to Group Filter on Collector (to push to FGT), or add this to FGT where FSSO Connector do have LDAP in config (which is there solely for this purpose, as FGT do not use it for group verification but just config).
    Then use above gained adgrp record in firewall user group type fsso, and this can be then used in policies (both on FGT).
    That's the way how to use Group filter.

    Tom xSilver, planet Earth, over and out!
    #4
    Alivo_ FTNT
    Expert Member
    • Total Posts : 97
    • Scores: 50
    • Reward points: 0
    • Joined: 2013/04/30 12:42:47
    • Location: Fortinet TAC Prague
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/26 05:23:06 (permalink)
    5 (1)
    Hello,
    Yes, the adgrp is the value of how many AD groups can be imported to FortiGate per vdom. It does not matter whether you config group filter from Collector Agent or from FortiGate using LDAP.

    Best Regards,
    Alivo
    #5
    hubertzw
    Gold Member
    • Total Posts : 202
    • Scores: 3
    • Reward points: 0
    • Joined: 2018/04/16 13:29:04
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/26 11:51:16 (permalink)
    0
    Maybe I wasn't clear in my answer. I know it's based on AD group not on specific users. Assuming I have 10000 groups, which represent different locations. I plan to add 1 or 2 entries (AD groups) for each FortiGate, what means I need to add up to 16k entries (filter groups). My question: is there any limit on the collector of entries I can add?
    #6
    xsilver_FTNT
    Expert Member
    • Total Posts : 551
    • Scores: 147
    • Reward points: 0
    • Joined: 2015/02/02 03:22:58
    • Location: EMEA
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/27 07:16:27 (permalink)
    0
    If you do have 10k FSSO groups, then you probably have overcomplicated setup.
    And I would not recommend to drive access by membership in hundreds of groups you already have and want to re-use, but make specific groups, according to access level you do want to grant to users (like P1Users with highest access, to P9Users with very limited access) and then add your existing users/groups to those access groups.
     
    Another alternative, if you do have many locations with local AD structure + FGT, then how about to have local collector, handling only users on the spot and making them FSSO to that local FGT?
    As you might not need all the users from around the globe (and nearest planets) on every single 30D access-FGT unit, right?
     
    Anyway.
    AFAIK there is no actual limit on how many groups can be inside the filter record known to me.
    BUT records are stored in registry keys and those do have limits : https://docs.microsoft.com/en-us/windows/win32/sysinfo/registry-element-size-limits
    Also, having too many groups will load them to FGT and that might cause troubles.
     
    So if you truly plan big deployment, then I would suggest to get in contact with Fortinets' Customer Care and through this channel with paid Professional Services team which can discus your specific setup and requirements and help you to size and even implement whole thing.

    Tom xSilver, planet Earth, over and out!
    #7
    hubertzw
    Gold Member
    • Total Posts : 202
    • Scores: 3
    • Reward points: 0
    • Joined: 2018/04/16 13:29:04
    • Status: offline
    Re: FSSO - collector agent - set group filters 2020/10/27 15:24:19 (permalink)
    0
    Thanks for your comments. I think a dedicated collector per site is not a good idea with 8k sites, I think it will be aggregated approach with one collector per X sites , in the same geographic region. I was curious what is the maximum value. FortiGate documentation is good when you need max values per each model. I couldn't find similar one just for collector agent. 
    #8
    Jump to:
    © 2020 APG vNext Commercial Version 5.5