Skip to main content
FortiKoala
Staff
Staff
October 1, 2018

Technical Tip: Event trigger latency when lost contact with Persistent Agent

  • October 1, 2018
  • 0 replies
  • 936 views

Description

 

This article describes an issue with the 'Persistent Agent Scan not performed' alarm not triggering right away when the Persistent Agent is no longer detected.  

 
Scope
 
FortiNAC.

Solution
 
Before the 'Persistent Agent Scan not performed' event is generated, the host record's MAC to IP must be resolved to check the host's status. If the information is not in the cache, the event will not trigger until the next L3 Poll is completed. This in turn delays the alarm trigger. 
 
Ensure L3 Polling is completed. This can be verified by navigating to Network Devices -> L3 Polling. The L3 Last Polled and L3 Last Poll Success should be the same timestamp.
 
l3poll.png

 

If the timestamp is not the same then further troubleshooting is needed.
Check this article for Troubleshooting Poll failures.
 
For more details and instructions on triggering alarms when the Persistent Agent stops scanning, refer to the Administration Guide.
 

mapping.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!