FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 194098
Description
Hosts Unexpectedly Marked 'At-Risk' for ForcePersistentAgent Scan

Scope
Version:   Network Sentry 8.1.4.4
Solution

Version:  Network Sentry 8.1.4.4


Issue:  Hosts unexpectedly getting marked At-Risk for ForcePersistentAgent System scan failure.  Host Health shows a status of "Failure" for the ForcePersistentAgent.  All other scans show a status of "Success" or "Initial." 

There are no alarms or scheduled tasks set to trigger it.


Workaround:  Under Host Health for the affected host, select the drill-down for the ForcePersistentAgent status and select either "Success" or "Initial" and save.  This will mark the host safe.


Solution:  Disable the ForcePersistentAgent System scan.   
Note:  If the scan is removed entirely, there is no way in the Admin UI to mark a host safe if they are failing for this scan. 

1. Navigate to Policy > Remediation Configuration.
2. Click the radial for Script/Profile entitled ForcePersistentAgent.
3. Click the Modify button.
4. Click Disable next to Status.
5. Click Apply.


For instructions on tracking hosts whose Persistent Agent is no longer communicating, download the document Detecting Persistent Agent Scans Not Performed.


Contributors