Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Troubleshooting Tip: Lost contact with Persistent Agent after updating from Version 2.x to 3.x or higher

  • September 28, 2018
  • 0 replies
  • 2400 views

Description

 
This article describes how to troubleshoot several issues after upgrading Hosts with Persistent Agent version 2.x to version 3.x or higher.


Scope

 

FortiNAC, Version: Persistent Agent version 3.x and higher.


Solution

 

Issue:  After updating hosts with Persistent Agent 2.x to version 3.x or higher, the agent stops communicating to Network Sentry.  Symptoms include:
  • Network Sentry reports 'Lost contact with Persistent Agent' events/alarms (indicates Network Sentry can no longer communicate to agent).
  • Network Sentry Hosts View does not reflect new agent version (even though the new version is installed).
  • Unable to scan host in Hosts View.
  • Unable to send message via Hosts View.
  • On the affected endstation, the error message 'SSL Certificate verification result: unable to get local issuer certificate' is printed in the following Persistent Agent log file (%ProgramData%Bradford Networksstderr.log on Windows, /var/log/bndaemon_stderr.txt on Mac OSX.)

Possible causes:
Missing Intermediate Certificate in Network Sentry.

To verify:
  1. Login to the Administrative UI and navigate to System -> Settings -> Security -> Certificate Management.  
  2. Highlight the Persistent Agent Certificate Target and select Details.
  3. Drill down on the Certificate Hierarchy and review the certificates listed. See Identify Missing SSL Certificates via Administrative UI.

Solution:  Install the missing intermediate certificate. If the customer does not have the original certificate files, the Intermediate Certificate files can be obtained.  See Identify Missing SSL Certificates via Administrative UI.  


Root certificate is not installed on affected host (which allows the certificate to be trusted):

Check to make sure that the host has the same root certificate as the one installed in Network Sentry for Persistent Agent communication.

To verify:
In the Administrative UI, navigate to System -> Settings -> Security -> Certificate Management and refer to the 'Issued By' field for the Persistent Agent target (for example, certs.godaddy.com).

Compare against certificates installed on the endstation. See Solution Verify Trusted Certificate Authorities on Windows or Mac OSX for instructions.

Solution:  Install the Root certificate on the endstation. This can be done by either browsing to the certificate authority, or installing the latest OS updates to acquire the root certificate.

See also Solution 1767: Login Prompt Does Not Appear After Downloading Persistent Agent 3.x or Higher.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!