Technical Tip: Scan settings in scan vs passive agent configuration
Description
This article describes the differences between the scan settings in an Endpoint Compliance Policy scan and the Passive Agent Configuration.
Scope
FortiNAC versions 8.x, 9.x & F 7.x.
Solution
The Passive Agent Configuration setting 'Scan unless previously scanned within...' is mutually exclusive with the Scan On Connect setting within the scan itself in the Endpoint Compliance Configuration.
- 'Scan On Connect' is triggered by line state (online versus offline).
- The Passive Agent Rule setting 'Scan unless previously scanned within' is based on login/logout activity.
See Manage configurations and Add or modify a scan in the Administration Guide for additional information.
