Description
This article describes the use of Dissolvable Agent during the remote registration process and the prompt that appears to input the server name.
Later agent versions require SSL certificate authentication, and therefore, need the application server's host name in order to connect.
The dissolvable agent uses SRV queries in an attempt to resolve the host name. The application server DNS configuration comes with built-in SRV records so the dissolvable agent's name resolution is resolved when the host is isolated.
When using public DNS or other DNS where these SRV records are not configured, the SRV queries are not answered. Consequently, the agent requires the end user to fill in the application Server URL.
Scope
FortiNAC, Dissolvable Agent.
Solution
Provide end user instructions in the portal page to enter the server's URL when prompted using format https://hostname.domain.tld
The portal page can be modified by navigating to Portal -> Portal Configuration.
The end user will be prompted to download and run a small program that will be able to verify that the computer does meet the network policies. When prompted for the Server URL, copy and paste the 'Fully-Qualified Host Name' that is configured in Portal -> Portal SSL for example: 'https://hostname.domain.tld' (without quotes) into the dialog.
Related articles:
Technical Tip: A simple network example of deploying VPN management with FortiGate
Troubleshooting Tip: Agent logs on end hosts
Technical Tip: A simple network example of deploying Persistent Agent in FortiNAC
Technical Tip: Dissolvable Agent: 'Unable to obtain configuration from server'
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.