Skip to main content
AD Academy
Network security: Fortinet
Intermediate16 minLast updated: Topic 9 of 14

FSSO — how the firewall knows who is who in AD

Mapping user-to-IP from DC logon events and firewall policies driven by AD groups.

Not read

What you will learn here

  • Related topics in this course
  • How it works
  • Two operating modes

Worth reading first:Logs and troubleshooting

A firewall thinks in IP addresses, but security policy is written in terms of users and groups: "accounting may, others may not". (Fortinet Single Sign-On) lets FortiGate learn which user sits behind which IP and apply policy by AD group.

The user logs into the domain, the DC writes Event 4624, the Collector Agent reads the log and sends FortiGate a user-to-IP mapping. Groups come from LDAP, so policy is written by AD group. Blind spots: shared PCs, IP changes and non-domain devices.

Short and clear

  • FSSO authenticates nobody — it only learns who already logged into the domain and from which IP.
  • The source is Event 4624 in the DC security log; groups come separately over LDAP.
  • Policy is written by group name ("G-Finance"), not by address, so it survives IP changes.
  • Shared PCs, BYOD or an unclean shutdown leave a stale mapping until the timeout.

Real-life exampleA user cannot reach the ERP although he is in the right group. diagnose debug authd fsso list shows his IP still mapped to the previous person who used that workstation.

Related topics in this course

  • Event ID 4624 — the same logon event the builds the mapping from (Event ID reference).
  • — HasSession answers the same question: who is logged on where (/course/tools/bloodhound-walkthrough).
  • Tiering — group based policy is how you enforce tier separation at the network level too.

How it works

  • The user logs into the domain — a normal logon, nothing new on the client.
  • A on the DC (or a dedicated server) reads the security log and sees logon event 4624.
  • The agent maps the user to the workstation IP and pushes that map to FortiGate (TCP, port 8000 by default).
  • FortiGate applies policy by group: CN=Teachers → allow rule, CN=Students → deny rule.

Two operating modes

  • Event Log / Polling mode — a on a dedicated server polls the DC for logon events.
  • Kerberos-based — a light agent on every DC watches authentication; scales better.
  • There is also Accounting based (for Wi-Fi) — same concept, a different source for the map.

Lab practice

  • Install the on a Windows server in the corp.local lab domain. Create service account svc-fsso with a non-expiring password and only Event Log Readers rights — never Admin.
  • In the set the DC, the FortiGate connection password and the port (8000 by default).
config user fsso-agent
    edit "FSSO-CA"
        set server "10.0.0.10"
        set password <password-from-collector-agent>
    next
end
bash

Now bind a FortiGate group to an group:

config user group
    edit "FSSO-Teachers"
        set member "FSSO-CA"
        config match
            edit 0
                set server-name "FSSO-CA"
                set group-name "CN=Teachers,OU=Groups,DC=corp,DC=local"
            next
        end
    next
end
bash

Then use the group in a policy (Policy & Objects → Firewall Policy → Source: FSSO-Teachers). Verify: from a workstation signed in as a Teachers member open a site — the session should appear under Security Fabric → User & Device → .

Risks and detection

  • The account: compromise means log access and influence over the map. Minimal rights, monitor 4624 events for that account.
  • Agent-to-FortiGate traffic is not a VPN — use an isolated management segment. This is Tier 0 communication.
  • Stale mappings: a workstation shut down improperly leaves the user-to-IP pair alive until timeout. Account for this in sensitive rules.

Mitigation

  • A dedicated management VLAN between FortiGate and the .
  • Agent account: Event Log Readers plus Deny interactive logon.
  • Regular audit: compare active sessions with real logons (quser / whoami on suspicious hosts).
  • Sensitive rules (Tier 1 server access) — match not only the group but also the segment IP range.

Check yourself

What is the source of the user-to-IP map in FSSO?

What rights are enough for the Collector Agent service account?

Why does an AD compromise make FSSO policy unreliable?

When can the user-to-IP map point at the wrong user?

Was this page helpful?