I would like to request a guide for configuring the Persistent Agent and Passive Agent. I’ve already tried following the official Fortinet guide, but it doesn’t seem to work, and I’m not sure why.
In my experiment, I was unable to deploy the agent through Active Directory, so I tried manually installing it on the AD user PCs instead. When the users are connected via a wired network, FortiNAC can detect the agent on the endpoints, but when they connect wirelessly, the agent is not detected.
Could you please help me with this issue by providing the appropriate configuration guide or documentation?
It seems like a connectivity issue to me not a configuration issue. When the user is on the wireless network, can you check if they can resolve the FQDN of FNAC? There may be different DNS addresses for the wireless network. Also, check the firewall logs for the agent communication ports, 4567 and 4568, to see if something is being blocked by the firewall policies.
You can check the logs from the user computer and share the output of the "general.txt" file with us by following the instructions in the document below.
If you leave the 'register as device' option unchecked, users will be asked to input their credentials as frequently as the authentication policy you have put in place. And yes, you'll still see the user registered to a device
| User | Count |
|---|---|
| 2691 | |
| 1412 | |
| 810 | |
| 711 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.