Skip to main content
Explorer
August 10, 2026
Solved

Persistent Agent remains 'Not Communicating' after reinstallation

  • August 10, 2026
  • 5 replies
  • 118 views

Hello,

I followed this technical tip:

Fortinet Technical Tip – Quickly isolate hosts that have disabled or uninstalled the Persistent Agent

It works very well when I stop and restart the Persistent Agent. The host is correctly detected as At-Risk, and I can see the VLAN change from the remediation VLAN back to the production VLAN as expected.

However, when I completely uninstall the Persistent Agent and then reinstall it, the host remains in "Agent Not Communicating" status. The status does not change after the agent has been reinstalled.

After reinstalling the agent, I have to delete the host from FortiNAC and restart the workstation before it is detected correctly again.

Is this expected behavior?

I also have a question regarding the following statement from the technical tip:

"An Event Mapping can be created that immediately changes the host status to 'At-Risk' as soon as an event 'Persistent Agent Not Communicating' is created."

Does this Event Mapping apply to all hosts, regardless of their location, including hosts that have never had the FortiNAC Persistent Agent installed?

Thank you for your help.

Best regards,

Best answer by ebilcari

After the agent is reinstalled, communication should start automatically, and the host status should return to Normal after a successful scan.

You should verify the network configuration and ensure that the subnet (Remediation or Quarantine VLAN) to which the host was moved can reach FNAC, either through the Isolation IP or the Management IP. Agent logs will give more details about the communication status.

When the host is deleted, it is classified as Rogue and moved to the Registration VLAN, which appears to have connectivity to FNAC.

The event "Persistent Agent Not Communicating" is triggered only for hosts that previously had a communicating agent. It will not affect other hosts that have never established agent communication.

5 replies

AEK
SuperUser
SuperUser
August 10, 2026

Regarding your first question, did you try restart the persistent agent service instead of restarting the host?

Regarding your second question, the “PA not communicating” is only related to hosts that have persistent agent installed and detected by FNAC. Other registered host that never had PA are not concerned by this.

AEK
mano972Author
Explorer
August 11, 2026

In the first case, I stop and restart the FortiNAC PA service, and the switch to the isolation VLAN works correctly.

In the second case, I uninstall the agent from the workstation. The workstation is then correctly moved to the isolation VLAN. However, when I reinstall the agent, I have to delete the endpoint from FortiNAC and restart the workstation before the PA is detected again.

 

Thank you for your response.

ebilcari
Staff
ebilcariAnswer
Staff
August 12, 2026

After the agent is reinstalled, communication should start automatically, and the host status should return to Normal after a successful scan.

You should verify the network configuration and ensure that the subnet (Remediation or Quarantine VLAN) to which the host was moved can reach FNAC, either through the Isolation IP or the Management IP. Agent logs will give more details about the communication status.

When the host is deleted, it is classified as Rogue and moved to the Registration VLAN, which appears to have connectivity to FNAC.

The event "Persistent Agent Not Communicating" is triggered only for hosts that previously had a communicating agent. It will not affect other hosts that have never established agent communication.

Emirjon
mano972Author
Explorer
August 14, 2026

You should verify the network configuration and ensure that the subnet (Remediation or Quarantine VLAN) to which the host was moved can reach FNAC, either through the Isolation IP or the Management IP. Agent logs will give more details about the communication status.

I have verified the network configuration and confirmed that communication with FNAC and from the Isolation, It’s OK.

I also checked the traffic with Wireshark directly from the workstation while it was in isolation, and I did not see any blocked or failed communication with FNAC.

However, even after reinstalling the Persistent Agent, the workstation does not automatically regain connectivity. It is still shown in FNAC as an "Agent Not Communicating" host, This is not a major issue in our case, but I wanted to mention it. Thank you

ebilcari
Staff
Staff
August 14, 2026

The agent logs on the endpoint, along with temporarily enabling these debug processes in FNAC, should provide more details for this behavior.
fnac76  # diagnose debug plugin enable AgentServer

fnac76  # diagnose debug plugin enable PersistentAgent

Based on the description, it seems like an old ‘token’ associated with the previous agent may be preventing communication from starting. I do not remember any complains or doing tests for this scenario.

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!