Chapter 3 Authentication for FortiOS 5.0 : Agent-based FSSO : Introduction to agent-based FSSO : FSSO for Windows AD
  
FSSO for Windows AD
FSSO for Windows AD requires at least one Collector agent. Domain Controller agents may also be required depending on the Collector agent working mode. There are two working modes to monitor user logon activity: DC Agent mode or Polling mode.
Table 25: Collector agent DC Agent mode versus Polling mode
 
DC Agent mode
Polling Mode
Installation
Complex — Multiple installations: one agent per DC plus Collector agent, requires a reboot
Easy — only Collector agent installation, no reboot required
Resources
Shares resources with DC system
Has own resources
Network load
Each DC agent requires minimum 64kpbs bandwidth, adding to network load
Increase polling period during busy period to reduce network load
Level of Confidence
Captures all logons
Potential to miss a login if polling period is too great