Skip to main content
Arjunpatil
Visitor III
July 10, 2025
Question

Fortisiem Windows agent status showing as disconnected in CMDB

  • July 10, 2025
  • 3 replies
  • 914 views

Environment Details:
Supervisor Version: 7.1.3 (MSP environment)
Windows Agent Version: 7.1.11 (also tested with 7.1.1)

HTTPS Proxy Configuration: Applied on Collector

Issue Summary:
Out of 5 Windows agents, 2 are showing "Running - Active" status, while the remaining 3 are showing "Disconnected" status on the Supervisor console.

Troubleshooting Performed:
Followed steps from the Fortinet Community article:
Windows Agent Registration with Supervisor.

Verified that HTTPS proxy configuration on the collector is correct (since 2 agents are successfully connected).

Test connection to the collector from affected agents is successful.

Upon reviewing the trace logs, it was observed that the agent is attempting to connect directly to the Supervisor, instead of using the collector.

Confirmed that Supervisor address field is blank under:
Admin -> Settings -> System -> Cluster Config -> Supervisors (This was already cleared as part of previous troubleshooting steps for a similar issue.)

Checked cat /var/log/httpd/ssl_access_log on collector and getting below error
10.11.125.5 - - [10/Jul/2025:06:06:09 -0500] "PUT /phoenix/rest/windowsAgent/update HTTP/1.0" 401 998
10.10.3.13 - 201353 [10/Jul/2025:06:06:13 -0500] "POST /winupload_direct?201353 HTTP/1.0" 200 -

Request:
Need assistance in identifying why the agent is bypassing the collector and attempting direct Supervisor communication, despite the setup being correct.

3 replies

Arjunpatil
Visitor III
July 14, 2025

Hi @AEK ,

Yes, I followed the steps from the article, but it doesn't provide a solution or workaround for the issue mentioned.


AlexPien
New Member
August 22, 2025

Hi, sometimes the webproxy configuration on the device is causing the issue. You have the possibility to install the FortiSIEM agent to use no Web Proxy. This will resolve a lot of proxy related incidents. Afterwards in the registry the value DISABLEPROXY = 1 will be created. 

 

Based on the current vulnerability in FortiSIEM I would recommand to upgrade to 7.3.4.

 

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!