FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
louvrosa
Staff
Staff
Article Id 417332
Description This article describes the difference between the 'Disconnected' and 'Disconnected (Expired)' FortiEDR Licensing Status. It provides an overview of what these statuses indicate and how they affect license allocation.
Scope FortiEDR.
Solution

The 'Disconnected' status indicates that the device on which the FortiEDR Collector is installed is either powered down or disconnected from the network. This status does not necessarily imply a problem with the FortiEDR Collector or the device itself.

 

The 'Disconnected (Expired)' status, on the other hand, is used to identify devices that have not been seen or communicated with the FortiEDR system for more than 30 days. This status helps in identifying devices that have been offline for an extended period. In case a device is not seen for a period of more than 30 days, the 'Disconnected (Expired)' status will be displayed for it, and its license will be released. If a device is brought back online after being offline for more than 30 days, it should reconnect to FortiEDR Manager, assuming there is at least one license slot available.

 

Here are some steps to consider:

  1. Check Last Communication: Verify when the device last communicated with the FortiEDR Manager. If it has been more than 30 days, the status will change to 'Disconnected (Expired)'.

  2. Network Configuration: Ensure that the network configuration allows the device to communicate with the FortiEDR Manager. There might be network policies or firewall rules blocking the communication.
    Use the Network Communication table below for firewall policy edit/creation: Technical Tip: FortiEDR Network Communication Requirements.

  3. Collector Status: Confirm that the FortiEDR Collector is running on the device. If the Collector is not running, it will not be able to communicate with the FortiEDR Manager.

  4. Reconnection: If the device is brought back online and there is at least one license slot available, it should reconnect to the FortiEDR Manager automatically.

  5. License Slot: If necessary, delete the Collector record from the FortiEDR Manager's inventory to release the license slot and allow the device to reconnect.

 

If the issue persists, further investigation into the specific network and device configuration may be required.