Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: Scan settings in scan vs passive agent configuration

  • September 28, 2018
  • 0 replies
  • 1139 views

Description

 
This article describes the differences between the scan settings in an Endpoint Compliance Policy scan and the Passive Agent Configuration.

 

Scope

 

FortiNAC versions 8.x, 9.x & F 7.x.


Solution

 

The Passive Agent Configuration setting 'Scan unless previously scanned within...' is mutually exclusive with the Scan On Connect setting within the scan itself in the Endpoint Compliance Configuration.

  • 'Scan On Connect' is triggered by line state (online versus offline).
  • The Passive Agent Rule setting 'Scan unless previously scanned within' is based on login/logout activity.

 

See Manage configurations and Add or modify a scan in the Administration Guide for additional information.