FSSO Flashcards
What is the recommended mode for FSSO?
DC Agent mode.
What are the two main components of DC Agent mode
DC Agent on Domain Controller
Collector Agent on a windows server.
What port does the FSSO collector Agent listen to?
8002
What port does the collector agent forward to FTG and what does it forward
8000
Username
Hostname
Ip add
User groups
Polling mode for FSSO can be agent or agentless based true or false
True
What are the components of agent based polling mode?
No agent on the DC
Just a collector on a Windows server
What does the agent based polling mode (FSSO) use to poll DC
By default it uses SMB port 445 top.
What are the three modes of polling based fsso
WMI
WinSecLog
NETapi
WMI
windows API DC returns all login events every 3 seconds
Reduced network load
WinSecLog
Polls all security events every 10.seconds
Slower but sees all events
NetAPI
polls the NetSessionEnum function on windows every 9 seconds
Table in RAM
Faster but can miss some events if bumped out of RAM
What ports does the polling based collector use
Listens on 445
Sends on 8000 to FTG
Agentless polling mode means?
That FTG does all of the polling of DCs, requires more resources
Is workstation verification available in agentless polling mode
No
What two WinSecLog ID does agentless mode use?
4768 and 4769