Additionally, Fortinet's proprietary protocols are documented, showing what FSSO. TCP/ (by default; this port can be customized). Outgoing ports. These include, but are not limited to the firewall rules described above, administrative actions and logging and tampering or misuse of the.

Each installation requires some maintenance as well. For these reasons it may not be possible to use the DC Agent mode. Each domain controller connection needs a minimum guaranteed 64kpbs bandwidth to ensure proper FSSO functionality. You can optionally configure traffic shapers on the FortiGate unit to ensure this minimum bandwidth is guaranteed for the domain controller connections. All share the advantages of being transparent and agentless. NetAPI polling is used to retrieve server logon sessions.

This includes the logon event information for the Controller agent. NetAPI runs faster than Event log polling but it may miss some user logon events under heavy system load. It requires a query round trip time of less than 10 seconds. Event log polling may run a bit slower, but will not miss events, even when the installation site has many users that require authentication.

It does not have the 10 second limit on NetAPI polling. Event log polling requires fast network links. This also reduces network load between CA and DC. In Polling mode, the Collector agent polls port of each domain controller for user logon information every few seconds and forwards it to the FortiGate unit.

There are no DC Agents installed, so the Collector agent polls the domain controllers directly. Polling mode results in a less complex install, and reduces ongoing maintenance. The Collector agent has two ways to access Active Directory user information. The main difference between Standard and Advanced mode is the naming convention used when referring to username information.

This mode is easier to set up, and is usually easier to maintain and troubleshoot. Hi Mike, I usually watch your videos and learn a lot from them, thank You. I wanna ask you something about this topic, In your experience, how many users are too many to use polling mode? Thanks a lot for reading. Save my name, email, and website in this browser for the next time I comment.

Notify me of follow-up comments by email. Notify me of new posts by email. This site uses Akismet to reduce spam. The connection must be successful before configuring the FSSO polling connector. To verify the configuration, hover the cursor over the top right corner of the connector; a popup window will show the currently selected groups.

A successful connection is also shown by a green up arrow in the lower right corner of the connector. If you need to get log in information from multiple DCs, then you must configure other Active Directory connectors for each additional DC to be monitored. FSSO groups can be used in a policy by either adding them to the policy directly, or by adding them to a local user group and then adding the group to a policy.

If the polling frequency shows successes and failures, that indicates sporadic network problems or a very busy DC. If it indicates no successes or failures, then incorrect credentials could be the issue.

This is required for AD group membership lookup of authenticated users because the Windows Security Event log does not include group membership information. Click Create New. Fill in the required information. Go to the Groups tab. Select the required groups, right click on them, and select Add Selected. The groups list can be filtered or searched to limit the number of groups that are displayed. Go to the Selected tab and verify that all the required groups are listed. Unneeded groups can be removed by right clicking and selecting Remove Selected.

Click OK. The Active Directory Connector is the front end connector that can be configured by FortiGate administrators.

