Version: Network Sentry 8.1.4.4
Issue: Hosts unexpectedly getting marked At-Risk for ForcePersistentAgent System scan failure. Host Health shows a status of "Failure" for the ForcePersistentAgent. All other scans show a status of "Success" or "Initial."
There are no alarms or scheduled tasks set to trigger it.
Workaround: Under Host Health for the affected host, select the drill-down for the ForcePersistentAgent status and select either "Success" or "Initial" and save. This will mark the host safe.
Solution: Disable the ForcePersistentAgent System scan.
Note: If the scan is removed entirely, there is no way in the Admin UI to mark a host safe if they are failing for this scan.
1. Navigate to Policy > Remediation Configuration.
2. Click the radial for Script/Profile entitled ForcePersistentAgent.
3. Click the Modify button.
4. Click Disable next to Status.
5. Click Apply.
For instructions on tracking hosts whose Persistent Agent is no longer communicating, download the document Detecting Persistent Agent Scans Not Performed.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.