Skip to main content
FortiKoala
Staff
Staff
September 27, 2018

Technical Tip: Isolating Hosts that no longer have a communicating Persistent Agent

  • September 27, 2018
  • 0 replies
  • 1577 views

Description

 

This article describes how to isolate hosts with the Persistent Agent that have lost contact with the appliance.  

Scope

 

Version: 8.x.

Solution

 
Option 1: Isolate host with option to reinstall the agent.
 
 
This option will…
  • Isolate the violating hosts to the VLAN for Quarantine (Remediation).
  • Allow for the re-installation of the persistent agent.  Once the agent is installed and communication is restored, the host will be allowed back onto the network.

Option 2: Isolate host (no option for reinstalling the agent).

This option will isolate the violating hosts by assigning a the 'Dead End' VLAN. The users are not offered a method for self-remediation.
 
  1. Create a dead end role.
  1. Navigate to Policy -> Roles -> Add.
  2. Enter Dead End for the name.
  3. Select OK.
  1. Enable the Lost Contact with Persistent Agent Event to Alarm Mapping.
  1. Navigate to Logs -> Event to Alarm Mappings.
  2. Add or double-click to modify.
  3. Select the enabled checkbox.
  4. Select a severity from the drop-down box (Critical).
  5. Select Clear on Event and select (Regained Contact with Persistent Agent).
  6. Select Trigger Rule and set to Event Frequency (4 events occurring within 1 hours).
  7. Check the checkbox for Action.
  8. Select Host Role Action in the drop-down box.
  9. Select the Dead End role in the Primary Task drop down.

 

  1. Create a Network Access Policy to restrict hosts with the 'Dead End' role.
  1. Navigate to Policy -> Policy Configuration -> Network Access Policy -> Add.
  2. Give the Network Access Policy a name (Lost Contact with Persistent Agent).
  3. Select the Add icon under User Host Profile.
  4. Give the User Host Profile a name (Lost Contact with Persistent Agent).
  5. Select Add in Who/What by Attribute.
  6. Select the host tab.
  7. Select the checkbox for the role under Policy -> Access.
  8. Type in Dead End.
  9. Select OK.
  10. Select the add icon under Network Access Configuration.
  11. Give the Network Access Configuration a name (Lost Contact with Persistent Agent).
  12. Type in the Dead End VLAN number.
  13. Select OK.
  14. Set the rank of the Network Access Policy as needed.

 

 

Related articles:

Technical Tip: Troubleshooting the Persistent Agent