Skip to main content
david_pereira
Staff & Editor
Staff & Editor
February 23, 2026

Technical Tip: Reasons for a FortiEDR collector to block network communications

  • February 23, 2026
  • 0 replies
  • 568 views
Description This article describes the reasons for FortiEDR collector to block some communications through the network.
Scope FortiEDR Collector
Solution

Possibility of blocking:


FortiEDR is designed to enforce security policies and make decisions about connection requests.
The FortiEDR Core acts as the decision-maker, determining whether a connection is legitimate or potentially malicious.
If an IP address is mistakenly classified as malicious or if there is a misconfiguration in the security policies, it is possible for FortiEDR to block external IP addresses, even if they are part of its own infrastructure.

 

Impact on collector behavior:

 

Intermittent behavior: If FortiEDR blocks legitimate IP addresses, it could indeed cause intermittent behavior in the Collector. This might manifest as stoppages, temporary loss of communication, or frequent re-connections. The Collector relies on communication with the Core for metadata analysis and authorization, so any disruption in this communication can lead to such issues.

 

Known scenarios for intermittency:

 

  1. Security Policies: Misconfigured security policies could inadvertently block legitimate traffic. It's important to review and adjust policies to ensure they align with the intended security posture.

  2. Reputation Services: If FortiEDR uses reputation services to classify IP addresses, errors or outdated information in these services could lead to incorrect blocking.

  3. Communication Errors: Network issues or errors in communication with FortiEDR's cloud services could also cause intermittent connectivity. This might be due to network latency, packet loss, or other connectivity issues.

  4. Core Unavailability: If all cores are unreachable, the Collector switches to autonomous mode, which might cause temporary changes in behavior until communication is re-established.

 

Follow-up actions:

  • Review Policies: Check the security policies configured in FortiEDR to ensure they are not overly restrictive or misconfigured.
  • Check Network Health: Investigate network connectivity to ensure there are no underlying issues affecting communication between the Collector and the Core.
  • Update Reputation Services: Ensure that any reputation services used are up-to-date and functioning correctly.
  • Monitor Logs: Use the Windows Event Viewer to monitor logs for any blocked communications or errors that might provide further insights into the issue.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.