Chapter 3 Authentication for FortiOS 5.0 : Agent-based FSSO : Agent installation : DC agent installation
  
DC agent installation
The FSSO_Setup file contains both the Collector agent and DC Agent installers, but the DC Agent installer is also available separately as either a .exe or .msi file named DCAgent_Setup.
To install the DC Agent
1. If you have just installed the Collector agent, the FSSO - Install DC Agent wizard starts automatically. Otherwise, go to Start > Programs > Fortinet > Fortinet Single Sign On Agent > Install DC Agent.
2. Select Next.
3. Read and accept the license agreement. Select Next.
4. Optionally, you can change the installation location. Select Next.
5. Enter the Collector agent IP address.
6. If the Collector agent computer has multiple network interfaces, ensure that the one that is listed is on your network. The listed Collector agent listening port is the default. Only change this if the port is already used by another service.
7. Select Next.
8. Select the domains to monitor and select Next.
9. If any of your required domains are not listed, cancel the wizard and set up the proper trusted relationship with the domain controller. Then run the wizard again by going to Start > Programs > Fortinet > Fortinet Single Sign On Agent > Install DC Agent.
10. Optionally, select users that you do not want monitored. These users will not be able to authenticate to FortiGate units using FSSO. You can also do this later. See “Configuring the FSSO Collector agent for Windows AD”.
11. Select Next.
12. Optionally, clear the check boxes of domain controllers on which you do not want to install the DC Agent.
13. Select the Working Mode as DC Agent Mode. While you can select Polling Mode here, in that situation you would not be installing a DC Agent. For more information, see “DC Agent mode” and “Polling mode”.
14. Select Next.
15. Select Yes when the wizard requests that you reboot the computer.
 
If you reinstall the FSSO software on this computer, your FSSO configuration is replaced with default settings.
If you want to create a redundant configuration, repeat the procedure “To install the Collector agent” on at least one other Windows AD server.
 
When you start to install a second Collector agent, cancel the Install Wizard dialog appears the second time. From the configuration GUI, the monitored domain controller list will show your domain controllers un-selected. Select the ones you wish to monitor with this Collector agent, and select Apply.
Before you can use FSSO, you need to configure it on both Windows AD and on the FortiGate units. “Configuring FSSO on FortiGate units” will help you accomplish these two tasks.