FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 192286
Description

ZoneFox agent can't connect to the Collector Server


Scope

Installation and Administration


Solution

When a ZoneFox agent is installed, it is configured to connect to the Collector Server (CS) via a URL which is of the format:


https://<CS_address>:8080


If the agent is unable to connect to the CS an error will be entered in the log file, located at C:Program Files (x86)Inquisitive SystemsCollectorManagerlogscms.log.


This issue can occur for a variety of reasons:


  1. An incorrect URL has been supplied to the agent
    Workaround:  Check the config file in C:Program Files (x86)Inquisitive SystemsCollectorManagercms.xml.  If changes are made to this file, stop and restart the Collector Manager service via the Task  Manager.
  2. Port 8080 is closed in the firewall
    Workaround:  Open port 8080 if possible, if this is not possible use https (port 443) for the CS and use http (port 80) for the ZoneFox console website, which can be locked down to access by only company IP-addresses if needed.
  3. A proxy server is blocking access
    Workaround:  Whitelist the ZoneFox DNS
  4. Your company antivirus (AV) software is blocking access
    Workaround:  Whitelist the ZoneFox DNS.  Depending on the AV being used you may need to whitelist the actual agent executable:

    On 64-bit machines this is located at:
         C:Program Files (x86)Inquisitive SystemsCollectorManagercms.exe
    On 32-bit machines this is located at:
         C:Program FilesInquisitive SystemsCollectorManagercms.exe






Contributors